CVE-2024-39507 (GCVE-0-2024-39507)
Vulnerability from cvelistv5
Published
2024-07-12 12:20
Modified
2026-08-05 11:33
Summary
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash problem in concurrent scenario When link status change, the nic driver need to notify the roce driver to handle this event, but at this time, the roce driver may uninit, then cause kernel crash. To fix the problem, when link status change, need to check whether the roce registered, and when uninit, need to wait link update finish.
Impacted products
Vendor Product Version
Linux Linux Version: 45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab
Version: 45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab
Version: 45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab
Version: 45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab
Version: 45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T21:56:27.927Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/62b5dfb67bfa8bd0301bf3442004563495f9ee48"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/6d0007f7b69d684879a0f598a042e40244d3cf63"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/b2c5024b771cd1dd8175d5f6949accfadbab7edd"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/12cda920212a49fa22d9e8b9492ac4ea013310a4"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-39507",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T17:06:51.352211Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:34:39.150Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_main.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "62b5dfb67bfa8bd0301bf3442004563495f9ee48",
              "status": "affected",
              "version": "45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab",
              "versionType": "git"
            },
            {
              "lessThan": "6d0007f7b69d684879a0f598a042e40244d3cf63",
              "status": "affected",
              "version": "45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab",
              "versionType": "git"
            },
            {
              "lessThan": "689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa",
              "status": "affected",
              "version": "45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab",
              "versionType": "git"
            },
            {
              "lessThan": "b2c5024b771cd1dd8175d5f6949accfadbab7edd",
              "status": "affected",
              "version": "45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab",
              "versionType": "git"
            },
            {
              "lessThan": "12cda920212a49fa22d9e8b9492ac4ea013310a4",
              "status": "affected",
              "version": "45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_main.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.1"
            },
            {
              "lessThan": "5.1",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.162",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.95",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.35",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.9.*",
              "status": "unaffected",
              "version": "6.9.6",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.10",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.162",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.95",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.35",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9.6",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix kernel crash problem in concurrent scenario\n\nWhen link status change, the nic driver need to notify the roce\ndriver to handle this event, but at this time, the roce driver\nmay uninit, then cause kernel crash.\n\nTo fix the problem, when link status change, need to check\nwhether the roce registered, and when uninit, need to wait link\nupdate finish."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is a PCI NIC driver\u0027s link-status handler reached via a local `SIOCETHTOOL`/ethtool-netlink call or the driver\u0027s own workqueue; no remote peer data is parsed and both the trigger and any heap grooming require local system access.\nAC:H - Exploitation requires winning a race between an in-flight `hclge_update_link_status()` and RoCE client teardown, and the teardown side is only initiated by module unload, driver unbind, hot-unplug, or device reset \u2014 an administrative event the attacker cannot cause, even though they can poll `ETHTOOL_GLINK` arbitrarily fast to hold the other side open.\nPR:L - `ETHTOOL_GLINK` is explicitly exempt from CAP_NET_ADMIN in `net/ethtool/ioctl.c`, so any unprivileged local user can repeatedly drive `hclge_get_status()` \u2192 `hclge_update_link_status()` and be positioned to groom the freed vmalloc\u0027d module region.\nUI:N - No victim must open a file, mount media, or otherwise be induced to act \u2014 the link update fires autonomously from the ~1 Hz periodic service task and from the attacker\u0027s own ethtool poll.\nS:U - The use-after-free corrupts kernel memory within the same security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - This is a use-after-free \u2014 the stale `rclient` is dereferenced in freed module memory and, where the RoCE callback exists, a freed `struct hns_roce_dev` is read via `ib_dispatch_port_state_event()`, giving an attacker who controls the reallocated contents a path to kernel memory disclosure.\nI:H - The UAF culminates in an indirect call through a function pointer read out of freed memory (`rclient-\u003eops-\u003elink_status_change`), a control-flow hijack primitive if the freed module pages are reclaimed with attacker-influenced data; the IB event dispatch also writes into the freed device structure.\nA:H - The reported and expected symptom is exactly a kernel crash \u2014 the commit is titled \"fix kernel crash problem in concurrent scenario\" \u2014 from dereferencing unmapped/freed module memory, which panics the system."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:33:50.288Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/62b5dfb67bfa8bd0301bf3442004563495f9ee48"
        },
        {
          "url": "https://git.kernel.org/stable/c/6d0007f7b69d684879a0f598a042e40244d3cf63"
        },
        {
          "url": "https://git.kernel.org/stable/c/689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa"
        },
        {
          "url": "https://git.kernel.org/stable/c/b2c5024b771cd1dd8175d5f6949accfadbab7edd"
        },
        {
          "url": "https://git.kernel.org/stable/c/12cda920212a49fa22d9e8b9492ac4ea013310a4"
        }
      ],
      "title": "net: hns3: fix kernel crash problem in concurrent scenario",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-39507",
    "datePublished": "2024-07-12T12:20:38.954Z",
    "dateReserved": "2024-06-25T14:23:23.752Z",
    "dateUpdated": "2026-08-05T11:33:50.288Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/62b5dfb67bfa8bd0301bf3442004563495f9ee48\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/6d0007f7b69d684879a0f598a042e40244d3cf63\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/b2c5024b771cd1dd8175d5f6949accfadbab7edd\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/12cda920212a49fa22d9e8b9492ac4ea013310a4\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T21:56:27.927Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-39507\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T17:06:51.352211Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:24.992Z\"}}], \"cna\": {\"title\": \"net: hns3: fix kernel crash problem in concurrent scenario\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab\", \"lessThan\": \"62b5dfb67bfa8bd0301bf3442004563495f9ee48\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab\", \"lessThan\": \"6d0007f7b69d684879a0f598a042e40244d3cf63\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab\", \"lessThan\": \"689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab\", \"lessThan\": \"b2c5024b771cd1dd8175d5f6949accfadbab7edd\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab\", \"lessThan\": \"12cda920212a49fa22d9e8b9492ac4ea013310a4\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_main.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.1\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.1\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.162\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.95\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.35\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9.6\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.9.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_main.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/62b5dfb67bfa8bd0301bf3442004563495f9ee48\"}, {\"url\": \"https://git.kernel.org/stable/c/6d0007f7b69d684879a0f598a042e40244d3cf63\"}, {\"url\": \"https://git.kernel.org/stable/c/689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa\"}, {\"url\": \"https://git.kernel.org/stable/c/b2c5024b771cd1dd8175d5f6949accfadbab7edd\"}, {\"url\": \"https://git.kernel.org/stable/c/12cda920212a49fa22d9e8b9492ac4ea013310a4\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nnet: hns3: fix kernel crash problem in concurrent scenario\\n\\nWhen link status change, the nic driver need to notify the roce\\ndriver to handle this event, but at this time, the roce driver\\nmay uninit, then cause kernel crash.\\n\\nTo fix the problem, when link status change, need to check\\nwhether the roce registered, and when uninit, need to wait link\\nupdate finish.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.162\", \"versionStartIncluding\": \"5.1\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.95\", \"versionStartIncluding\": \"5.1\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.35\", \"versionStartIncluding\": \"5.1\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9.6\", \"versionStartIncluding\": \"5.1\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10\", \"versionStartIncluding\": \"5.1\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2025-05-04T09:17:17.593Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-39507\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-11-03T21:56:27.927Z\", \"dateReserved\": \"2024-06-25T14:23:23.752Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-07-12T12:20:38.954Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…