CVE-2024-39507

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-39507
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-39507.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-39507
Downstream
Related
Published
2024-07-12T12:20:38.954Z
Modified
2025-11-28T02:34:11.787947Z
Summary
net: hns3: fix kernel crash problem in concurrent scenario
Details

In the Linux kernel, the following vulnerability has been resolved:

net: hns3: fix kernel crash problem in concurrent scenario

When link status change, the nic driver need to notify the roce driver to handle this event, but at this time, the roce driver may uninit, then cause kernel crash.

To fix the problem, when link status change, need to check whether the roce registered, and when uninit, need to wait link update finish.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39507.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
45e92b7e4e27a427de7e87d5c4d63d4ce7ba02ab
Fixed
62b5dfb67bfa8bd0301bf3442004563495f9ee48
Fixed
6d0007f7b69d684879a0f598a042e40244d3cf63
Fixed
689de7c3bfc7d47e0eacc641c4ce4a0f579aeefa
Fixed
b2c5024b771cd1dd8175d5f6949accfadbab7edd
Fixed
12cda920212a49fa22d9e8b9492ac4ea013310a4

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1.0
Fixed
5.15.162
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.95
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.35
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.9.6