#VU92362 Improper locking in Linux kernel - CVE-2024-38595
Published: June 20, 2024 / Updated: May 13, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the mlx5_sf_dev_probe() function in drivers/net/ethernet/mellanox/mlx5/core/sf/dev/driver.c, within the mlx5_init_one_light() function in drivers/net/ethernet/mellanox/mlx5/core/main.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/a0501201751034ebe7a22bd9483ed28fea1cd213
- https://git.kernel.org/stable/c/05d9d7b66836d87c914f8fdd4b062b78e373458d
- https://git.kernel.org/stable/c/3c453e8cc672de1f9c662948dba43176bc68d7f0
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.10
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8.12