CVE Database
/

CVE-2024-38556

Back to search

CVE-2024-38556

Published: Jun 19, 2024

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Add a timeout to acquire the command queue semaphore Prevent forced completion handling on an entry that has not yet been assigned an index, causing an out of bounds access on idx = -22. Instead of waiting indefinitely for the sem, blocking flow now waits for index to be allocated or a sem acquisition timeout before beginning the timer for FW completion. Kernel log example: mlx5_core 0000:06:00.0: wait_func_handle_exec_timeout:1128:(pid 185911): cmd[-22]: CREATE_UCTX(0xa04) No done completion

VendorProductVersions

Linux

Linux

affected
8e715cd613a1e872b9d918e912d90b399785761a - < 4baae687a20ef2b82fde12de3c04461e6f2521d6
affected
8e715cd613a1e872b9d918e912d90b399785761a - < f9caccdd42e999b74303c9b0643300073ed5d319
affected
8e715cd613a1e872b9d918e912d90b399785761a - < 2d0962d05c93de391ce85f6e764df895f47c8918
affected
8e715cd613a1e872b9d918e912d90b399785761a - < 94024332a129c6e4275569d85c0c1bfb2ae2d71b
affected
8e715cd613a1e872b9d918e912d90b399785761a - < 485d65e1357123a697c591a5aeb773994b247ad7

+8 more versions

Linux

Linux

affected
5.17
unaffected
0 - < 5.17
unaffected
6.1.93 - <= 6.1.*
unaffected
6.6.33 - <= 6.6.*
unaffected
6.8.12 - <= 6.8.*

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now