{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-39507", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-06-25T14:23:23.752Z", "datePublished": "2024-07-12T12:20:38.954Z", "dateUpdated": "2026-08-05T11:33:50.288Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:33:50.288Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix kernel crash problem in concurrent scenario\n\nWhen link status change, the nic driver need to notify the roce\ndriver to handle this event, but at this time, the roce driver\nmay uninit, then cause kernel crash.\n\nTo fix the problem, when link status change, need to check\nwhether the roce registered, and when uninit, need to wait link\nupdate finish." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable code is a PCI NIC driver's link-status handler reached via a local `SIOCETHTOOL`/ethtool-netlink call or the driver's own workqueue; no remote peer data is parsed and both the trigger and any heap grooming require local system access.\nAC:H - Exploitation requires winning a race between an in-flight `hclge_update_link_status()` and RoCE client teardown, and the teardown side is only initiated by module unload, driver unbind, hot-unplug, or device reset — an administrative event the attacker cannot cause, even though they can poll `ETHTOOL_GLINK` arbitrarily fast to hold the other side open.\nPR:L - `ETHTOOL_GLINK` is explicitly exempt from CAP_NET_ADMIN in `net/ethtool/ioctl.c`, so any unprivileged local user can repeatedly drive `hclge_get_status()` → `hclge_update_link_status()` and be positioned to groom the freed vmalloc'd module region.\nUI:N - No victim must open a file, mount media, or otherwise be induced to act — the link update fires autonomously from the ~1 Hz periodic service task and from the attacker's own ethtool poll.\nS:U - The use-after-free corrupts kernel memory within the same security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - This is a use-after-free — the stale `rclient` is dereferenced in freed module memory and, where the RoCE callback exists, a freed `struct hns_roce_dev` is read via `ib_dispatch_port_state_event()`, giving an attacker who controls the reallocated contents a path to kernel memory disclosure.\nI:H - The UAF culminates in an indirect call through a function pointer read out of freed memory (`rclient->ops->link_status_change`), a control-flow hijack primitive if the freed module pages are reclaimed with attacker-influenced data; the IB event dispatch also writes into the freed device structure.\nA:H - The reported and expected symptom is exactly a kernel crash — the commit is titled \"fix kernel crash problem in concurrent scenario\" — from dereferencing unmapped/freed module memory, which panics the system." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_main.c" ], "versions": [ { "version": "45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab", "lessThan": "62b5dfb67bfa8bd0301bf3442004563495f9ee48", "status": "affected", "versionType": "git" }, { "version": "45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab", "lessThan": "6d0007f7b69d684879a0f598a042e40244d3cf63", "status": "affected", "versionType": "git" }, { "version": "45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab", "lessThan": "689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa", "status": "affected", "versionType": "git" }, { "version": "45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab", "lessThan": "b2c5024b771cd1dd8175d5f6949accfadbab7edd", "status": "affected", "versionType": "git" }, { "version": "45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab", "lessThan": "12cda920212a49fa22d9e8b9492ac4ea013310a4", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_main.c" ], "versions": [ { "version": "5.1", "status": "affected" }, { "version": "0", "lessThan": "5.1", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.162", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.95", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.35", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.9.6", "lessThanOrEqual": "6.9.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.10", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.1", "versionEndExcluding": "5.15.162" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.1", "versionEndExcluding": "6.1.95" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.1", "versionEndExcluding": "6.6.35" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.1", "versionEndExcluding": "6.9.6" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.1", "versionEndExcluding": "6.10" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/62b5dfb67bfa8bd0301bf3442004563495f9ee48" }, { "url": "https://git.kernel.org/stable/c/6d0007f7b69d684879a0f598a042e40244d3cf63" }, { "url": "https://git.kernel.org/stable/c/689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa" }, { "url": "https://git.kernel.org/stable/c/b2c5024b771cd1dd8175d5f6949accfadbab7edd" }, { "url": "https://git.kernel.org/stable/c/12cda920212a49fa22d9e8b9492ac4ea013310a4" } ], "title": "net: hns3: fix kernel crash problem in concurrent scenario", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "title": "CVE Program Container", "references": [ { "url": "https://git.kernel.org/stable/c/62b5dfb67bfa8bd0301bf3442004563495f9ee48", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/6d0007f7b69d684879a0f598a042e40244d3cf63", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/b2c5024b771cd1dd8175d5f6949accfadbab7edd", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/12cda920212a49fa22d9e8b9492ac4ea013310a4", "tags": [ "x_transferred" ] }, { "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T21:56:27.927Z" } }, { "metrics": [ { "other": { "type": "ssvc", "content": { "id": "CVE-2024-39507", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2024-09-10T17:06:51.352211Z" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-11T17:34:39.150Z" } } ] } }