CVE-2024-36900

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when devlink reload during initialization The devlink reload process will access the hardware resources, but the register operation is done before the hardware is initialized. So, processing the devlink reload during initialization may lead to kernel crash. This patch fixes this by registering the devlink after hardware initialization.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc7:*:*:*:*:*:*

History

30 Sep 2025, 17:49

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-908
References () https://git.kernel.org/stable/c/35d92abfbad88cf947c010baf34b075e40566095 - () https://git.kernel.org/stable/c/35d92abfbad88cf947c010baf34b075e40566095 - Patch
References () https://git.kernel.org/stable/c/5c623fe0534806b627054da09b6f51b7b2f7b9cd - () https://git.kernel.org/stable/c/5c623fe0534806b627054da09b6f51b7b2f7b9cd - Patch
References () https://git.kernel.org/stable/c/72ede790f5a03c3957487400a1b72ebce293a2e7 - () https://git.kernel.org/stable/c/72ede790f5a03c3957487400a1b72ebce293a2e7 - Patch
References () https://git.kernel.org/stable/c/c98bc78ce0909ccc92005e2cb6609ec6c7942f69 - () https://git.kernel.org/stable/c/c98bc78ce0909ccc92005e2cb6609ec6c7942f69 - Patch

21 Nov 2024, 09:22

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/35d92abfbad88cf947c010baf34b075e40566095 - () https://git.kernel.org/stable/c/35d92abfbad88cf947c010baf34b075e40566095 -
References () https://git.kernel.org/stable/c/5c623fe0534806b627054da09b6f51b7b2f7b9cd - () https://git.kernel.org/stable/c/5c623fe0534806b627054da09b6f51b7b2f7b9cd -
References () https://git.kernel.org/stable/c/72ede790f5a03c3957487400a1b72ebce293a2e7 - () https://git.kernel.org/stable/c/72ede790f5a03c3957487400a1b72ebce293a2e7 -
References () https://git.kernel.org/stable/c/c98bc78ce0909ccc92005e2cb6609ec6c7942f69 - () https://git.kernel.org/stable/c/c98bc78ce0909ccc92005e2cb6609ec6c7942f69 -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: hns3: soluciona el fallo del kernel cuando devlink se recarga durante la inicialización El proceso de recarga de devlink accederá a los recursos de hardware, pero la operación de registro se realiza antes de que se inicialice el hardware. Por lo tanto, procesar la recarga de devlink durante la inicialización puede provocar una falla del kernel. Este parche soluciona este problema registrando el devlink después de la inicialización del hardware.

30 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-30 16:15

Updated : 2025-09-30 17:49


NVD link : CVE-2024-36900

Mitre link : CVE-2024-36900

CVE.ORG link : CVE-2024-36900


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-908

Use of Uninitialized Resource