Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: eth: sungem: remove .ndo_poll_controller to avoid deadlocks Erhard reports netpoll warnings from sungem: netpoll_send_skb_on_dev(): eth0 enabled interrupts in poll (gem_start_xmit+0x0/0x398) WARNING: CPU: 1 PID: 1 at net/core/netpoll.c:370 netpoll_send_skb+0x1fc/0x20c gem_poll_controller() disables interrupts, which may sleep. We can't sleep in netpoll, it has interrupts disabled completely. Strangely, gem_poll_controller() doesn't even poll the completions, and instead acts as if an interrupt has fired so it just schedules NAPI and exits. None of this has been necessary for years, since netpoll invokes NAPI directly.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.1, < 5.10.219 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/476adb3bbbd7886e8251d3b9ce2d3c3e680f35d6Patch
- https://git.kernel.org/stable/c/5de5aeb98f9a000adb0db184e32765e4815d860bPatch
- https://git.kernel.org/stable/c/6400d205fbbcbcf9b8510157e1f379c1d7e2e937Patch
- https://git.kernel.org/stable/c/ac0a230f719b02432d8c7eba7615ebd691da86f4Patch
- https://git.kernel.org/stable/c/e22b23f5888a065d084e87db1eec639c445e677fPatch
- https://git.kernel.org/stable/c/faf94f1eb8a34b2c31b2042051ef36f63420eccePatch
- https://git.kernel.org/stable/c/fbeeb55dbb33d562149c57e794f06b7414e44289Patch
- https://git.kernel.org/stable/c/476adb3bbbd7886e8251d3b9ce2d3c3e680f35d6Patch
- https://git.kernel.org/stable/c/5de5aeb98f9a000adb0db184e32765e4815d860bPatch
- https://git.kernel.org/stable/c/6400d205fbbcbcf9b8510157e1f379c1d7e2e937Patch
- https://git.kernel.org/stable/c/ac0a230f719b02432d8c7eba7615ebd691da86f4Patch
- https://git.kernel.org/stable/c/e22b23f5888a065d084e87db1eec639c445e677fPatch
- https://git.kernel.org/stable/c/faf94f1eb8a34b2c31b2042051ef36f63420eccePatch
- https://git.kernel.org/stable/c/fbeeb55dbb33d562149c57e794f06b7414e44289Patch
FAQ
What is CVE-2024-38597?
CVE-2024-38597 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: eth: sungem: remove .ndo_poll_controller to avoid deadlocks Erhard reports netpoll warnings from sungem: netpoll_send_skb_on_de...
How severe is CVE-2024-38597?
CVE-2024-38597 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38597?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.