Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-38556
HistoryJun 19, 2024 - 12:00 a.m.

CVE-2024-38556

2024-06-1900:00:00
ubuntu.com
ubuntu.com
4
linux kernel
net/mlx5
vulnerability
semaphore
out of bounds access

AI Score

6.7

Confidence

High

In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Add a timeout to acquire the command queue semaphore Prevent
forced completion handling on an entry that has not yet been assigned an
index, causing an out of bounds access on idx = -22. Instead of waiting
indefinitely for the sem, blocking flow now waits for index to be allocated
or a sem acquisition timeout before beginning the timer for FW completion.
Kernel log example: mlx5_core 0000:06:00.0:
wait_func_handle_exec_timeout:1128:(pid 185911): cmd[-22]:
CREATE_UCTX(0xa04) No done completion