CVE-2024-38556
Description
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Add a timeout to acquire the command queue semaphore Prevent forced completion handling on an entry that has not yet been assigned an index, causing an out of bounds access on idx = -22. Instead of waiting indefinitely for the sem, blocking flow now waits for index to be allocated or a sem acquisition timeout before beginning the timer for FW completion. Kernel log example: mlx5_core 0000:06:00.0: wait_func_handle_exec_timeout:1128:(pid 185911): cmd[-22]: CREATE_UCTX(0xa04) No done completion
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| sles | affected | | |
| rocky | 9 | fixed | |
| debian | bookworm | fixed | 6.1.94-1 |
| debian | bullseye | affected | |
| debian | forky | fixed | 6.8.12-1 |
| debian | sid | fixed | 6.8.12-1 |
| debian | trixie | fixed | 6.8.12-1 |
| almalinux | 9 | fixed | kernel-debug-devel-matched-5.14.0-427.40.1.el9_4.aarch64.rpm |
References
- https://access.redhat.com/errata/RHSA-2024:8162
- https://www.suse.com/security/cve/CVE-2024-38556.html
- https://errata.rockylinux.org/RLSA-2024:8162
- https://security-tracker.debian.org/tracker/CVE-2024-38556
- https://bugzilla.redhat.com/2270700
- https://bugzilla.redhat.com/2281127
- https://bugzilla.redhat.com/2281149
- https://bugzilla.redhat.com/2281847
- https://bugzilla.redhat.com/2282355
- https://bugzilla.redhat.com/2284571
- https://bugzilla.redhat.com/2293078
- https://bugzilla.redhat.com/2293443
- https://bugzilla.redhat.com/2295921
- https://bugzilla.redhat.com/2297474
- https://bugzilla.redhat.com/2297543
- https://bugzilla.redhat.com/2300517
- https://errata.almalinux.org/9/ALSA-2024-8162.html
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.