CVE-2024-38544 (GCVE-0-2024-38544)
Vulnerability from cvelistv5
Published
2024-06-19 13:35
Modified
2026-08-05 11:32
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt In rxe_comp_queue_pkt() an incoming response packet skb is enqueued to the resp_pkts queue and then a decision is made whether to run the completer task inline or schedule it. Finally the skb is dereferenced to bump a 'hw' performance counter. This is wrong because if the completer task is already running in a separate thread it may have already processed the skb and freed it which can cause a seg fault. This has been observed infrequently in testing at high scale. This patch fixes this by changing the order of enqueuing the packet until after the counter is accessed.
Impacted products
Vendor Product Version
Linux Linux Version: 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0
Version: 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0
Version: 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0
Version: 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0
Version: 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0
Version: 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0
Version: 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0
Version: 0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "HIGH",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 6.3,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-38544",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-20T15:44:10.125327Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "description": "CWE-noinfo Not enough information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-11-06T16:19:22.930Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T20:38:08.626Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/21b4c6d4d89030fd4657a8e7c8110fd941049794"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/bbad88f111a1829f366c189aa48e7e58e57553fc"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/30df4bef8b8e183333e9b6e9d4509d552c7da6eb"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/2b23b6097303ed0ba5f4bc036a1c07b6027af5c6"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/sw/rxe/rxe_comp.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "c91fb72a2ca6480d8d77262eef52dc5b178463a3",
              "status": "affected",
              "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
              "versionType": "git"
            },
            {
              "lessThan": "de5a059e36657442b5637cc16df5163e435b9cb4",
              "status": "affected",
              "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
              "versionType": "git"
            },
            {
              "lessThan": "e0e14dd35d4242340c7346aac60c7ff8fbf87ffc",
              "status": "affected",
              "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
              "versionType": "git"
            },
            {
              "lessThan": "faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19",
              "status": "affected",
              "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
              "versionType": "git"
            },
            {
              "lessThan": "21b4c6d4d89030fd4657a8e7c8110fd941049794",
              "status": "affected",
              "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
              "versionType": "git"
            },
            {
              "lessThan": "bbad88f111a1829f366c189aa48e7e58e57553fc",
              "status": "affected",
              "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
              "versionType": "git"
            },
            {
              "lessThan": "30df4bef8b8e183333e9b6e9d4509d552c7da6eb",
              "status": "affected",
              "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
              "versionType": "git"
            },
            {
              "lessThan": "2b23b6097303ed0ba5f4bc036a1c07b6027af5c6",
              "status": "affected",
              "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/sw/rxe/rxe_comp.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.12"
            },
            {
              "lessThan": "4.12",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.285",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.227",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.168",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.93",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.33",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.12",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.9.*",
              "status": "unaffected",
              "version": "6.9.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.10",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.285",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.227",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.168",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.93",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.33",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.12",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9.3",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10",
                  "versionStartIncluding": "4.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix seg fault in rxe_comp_queue_pkt\n\nIn rxe_comp_queue_pkt() an incoming response packet skb is enqueued to the\nresp_pkts queue and then a decision is made whether to run the completer\ntask inline or schedule it. Finally the skb is dereferenced to bump a \u0027hw\u0027\nperformance counter. This is wrong because if the completer task is\nalready running in a separate thread it may have already processed the skb\nand freed it which can cause a seg fault.  This has been observed\ninfrequently in testing at high scale.\n\nThis patch fixes this by changing the order of enqueuing the packet until\nafter the counter is accessed."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable function is reached directly from the Soft-RoCE UDP encapsulation receive handler on port 4791 (rxe_udp_encap_recv \u2192 rxe_rcv \u2192 rxe_rcv_pkt \u2192 rxe_comp_queue_pkt), processing data from a remote peer. RoCEv2 is routable IP/UDP traffic, so the attacker is not confined to the local L2 segment.\nAC:L - The attacker controls both sides of the race: the vulnerable counter access only occurs when resp_pkts already holds another packet (queue_len \u003e 1), a condition created by bursting response packets while the completer work item concurrently drains and kfree_skb()s them on another CPU. The commit describes it triggering under high packet load, which is exactly what an attacker-driven flood produces.\nPR:N - RoCEv2 provides no authentication; the only checks before the UAF are QPN lookup, QP state, source/destination IP matching the QP\u0027s address vector, default pkey, and a plain CRC32 ICRC that any attacker can compute. A malicious or compromised RDMA peer, or an attacker spoofing the peer\u0027s source address, needs no credentials on the target system.\nUI:N - Exploitation requires only that the target have an active RC/UC queue pair in RTS state, which is the normal steady-state operating condition of an RDMA connection. No action by any local user or administrator is needed at attack time.\nS:U - The use-after-free corrupts kernel slab memory and is exploited within the kernel\u0027s own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The freed skb\u0027s control block is read after kfree_skb(), so the attacker can groom the reallocated slab object to source the rxe pointer, and a use-after-free on the skb slab is a classic primitive for leaking adjacent kernel memory and defeating KASLR.\nI:H - The stale pointer read from the freed object is immediately passed to rxe_counter_inc(), which performs atomic64_inc(\u0026rxe-\u003estats_counters[index]) \u2014 a write through an attacker-influenceable pointer, giving a targeted 64-bit increment primitive that can corrupt arbitrary kernel structures and be escalated to control-flow hijack.\nA:H - The commit explicitly reports a segmentation fault (kernel oops) from this dereference, and any unresolved use-after-free of an skb reliably crashes or panics the kernel, which a remote attacker can trigger repeatedly."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:32:41.788Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c91fb72a2ca6480d8d77262eef52dc5b178463a3"
        },
        {
          "url": "https://git.kernel.org/stable/c/de5a059e36657442b5637cc16df5163e435b9cb4"
        },
        {
          "url": "https://git.kernel.org/stable/c/e0e14dd35d4242340c7346aac60c7ff8fbf87ffc"
        },
        {
          "url": "https://git.kernel.org/stable/c/faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19"
        },
        {
          "url": "https://git.kernel.org/stable/c/21b4c6d4d89030fd4657a8e7c8110fd941049794"
        },
        {
          "url": "https://git.kernel.org/stable/c/bbad88f111a1829f366c189aa48e7e58e57553fc"
        },
        {
          "url": "https://git.kernel.org/stable/c/30df4bef8b8e183333e9b6e9d4509d552c7da6eb"
        },
        {
          "url": "https://git.kernel.org/stable/c/2b23b6097303ed0ba5f4bc036a1c07b6027af5c6"
        }
      ],
      "title": "RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-38544",
    "datePublished": "2024-06-19T13:35:18.676Z",
    "dateReserved": "2024-06-18T19:36:34.919Z",
    "dateUpdated": "2026-08-05T11:32:41.788Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/21b4c6d4d89030fd4657a8e7c8110fd941049794\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/bbad88f111a1829f366c189aa48e7e58e57553fc\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/30df4bef8b8e183333e9b6e9d4509d552c7da6eb\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/2b23b6097303ed0ba5f4bc036a1c07b6027af5c6\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T20:38:08.626Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 6.3, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"HIGH\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-38544\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-06-20T15:44:10.125327Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"description\": \"CWE-noinfo Not enough information\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-06-20T15:44:16.244Z\"}}], \"cna\": {\"title\": \"RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 9.8, \"baseSeverity\": \"CRITICAL\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - The vulnerable function is reached directly from the Soft-RoCE UDP encapsulation receive handler on port 4791 (rxe_udp_encap_recv \\u2192 rxe_rcv \\u2192 rxe_rcv_pkt \\u2192 rxe_comp_queue_pkt), processing data from a remote peer. RoCEv2 is routable IP/UDP traffic, so the attacker is not confined to the local L2 segment.\\nAC:L - The attacker controls both sides of the race: the vulnerable counter access only occurs when resp_pkts already holds another packet (queue_len \u003e 1), a condition created by bursting response packets while the completer work item concurrently drains and kfree_skb()s them on another CPU. The commit describes it triggering under high packet load, which is exactly what an attacker-driven flood produces.\\nPR:N - RoCEv2 provides no authentication; the only checks before the UAF are QPN lookup, QP state, source/destination IP matching the QP\u0027s address vector, default pkey, and a plain CRC32 ICRC that any attacker can compute. A malicious or compromised RDMA peer, or an attacker spoofing the peer\u0027s source address, needs no credentials on the target system.\\nUI:N - Exploitation requires only that the target have an active RC/UC queue pair in RTS state, which is the normal steady-state operating condition of an RDMA connection. No action by any local user or administrator is needed at attack time.\\nS:U - The use-after-free corrupts kernel slab memory and is exploited within the kernel\u0027s own security authority. No VM, IOMMU, or sandbox boundary is crossed.\\nC:H - The freed skb\u0027s control block is read after kfree_skb(), so the attacker can groom the reallocated slab object to source the rxe pointer, and a use-after-free on the skb slab is a classic primitive for leaking adjacent kernel memory and defeating KASLR.\\nI:H - The stale pointer read from the freed object is immediately passed to rxe_counter_inc(), which performs atomic64_inc(\u0026rxe-\u003estats_counters[index]) \\u2014 a write through an attacker-influenceable pointer, giving a targeted 64-bit increment primitive that can corrupt arbitrary kernel structures and be escalated to control-flow hijack.\\nA:H - The commit explicitly reports a segmentation fault (kernel oops) from this dereference, and any unresolved use-after-free of an skb reliably crashes or panics the kernel, which a remote attacker can trigger repeatedly.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0\", \"lessThan\": \"c91fb72a2ca6480d8d77262eef52dc5b178463a3\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0\", \"lessThan\": \"de5a059e36657442b5637cc16df5163e435b9cb4\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0\", \"lessThan\": \"e0e14dd35d4242340c7346aac60c7ff8fbf87ffc\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0\", \"lessThan\": \"faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0\", \"lessThan\": \"21b4c6d4d89030fd4657a8e7c8110fd941049794\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0\", \"lessThan\": \"bbad88f111a1829f366c189aa48e7e58e57553fc\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0\", \"lessThan\": \"30df4bef8b8e183333e9b6e9d4509d552c7da6eb\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0\", \"lessThan\": \"2b23b6097303ed0ba5f4bc036a1c07b6027af5c6\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/infiniband/sw/rxe/rxe_comp.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.12\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.12\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.4.285\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.227\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.168\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.93\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.33\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.12\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.9.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/infiniband/sw/rxe/rxe_comp.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/c91fb72a2ca6480d8d77262eef52dc5b178463a3\"}, {\"url\": \"https://git.kernel.org/stable/c/de5a059e36657442b5637cc16df5163e435b9cb4\"}, {\"url\": \"https://git.kernel.org/stable/c/e0e14dd35d4242340c7346aac60c7ff8fbf87ffc\"}, {\"url\": \"https://git.kernel.org/stable/c/faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19\"}, {\"url\": \"https://git.kernel.org/stable/c/21b4c6d4d89030fd4657a8e7c8110fd941049794\"}, {\"url\": \"https://git.kernel.org/stable/c/bbad88f111a1829f366c189aa48e7e58e57553fc\"}, {\"url\": \"https://git.kernel.org/stable/c/30df4bef8b8e183333e9b6e9d4509d552c7da6eb\"}, {\"url\": \"https://git.kernel.org/stable/c/2b23b6097303ed0ba5f4bc036a1c07b6027af5c6\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nRDMA/rxe: Fix seg fault in rxe_comp_queue_pkt\\n\\nIn rxe_comp_queue_pkt() an incoming response packet skb is enqueued to the\\nresp_pkts queue and then a decision is made whether to run the completer\\ntask inline or schedule it. Finally the skb is dereferenced to bump a \u0027hw\u0027\\nperformance counter. This is wrong because if the completer task is\\nalready running in a separate thread it may have already processed the skb\\nand freed it which can cause a seg fault.  This has been observed\\ninfrequently in testing at high scale.\\n\\nThis patch fixes this by changing the order of enqueuing the packet until\\nafter the counter is accessed.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.285\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.227\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.168\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.93\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.33\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.12\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9.3\", \"versionStartIncluding\": \"4.12\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10\", \"versionStartIncluding\": \"4.12\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:32:41.788Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-38544\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:32:41.788Z\", \"dateReserved\": \"2024-06-18T19:36:34.919Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-06-19T13:35:18.676Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…