CVE-2024-26838

MEDIUM

Linux Kernel 5.14-5.15.150, 5.16-6.1.80, 6.2-6.6.19, 6.7-6.7.7 - Use-After-Free in IRDMA Tasklet Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix KASAN issue with tasklet KASAN testing revealed the following issue assocated with freeing an IRQ. [50006.466686] Call Trace: [50006.466691] <IRQ> [50006.489538] dump_stack+0x5c/0x80 [50006.493475] print_address_description.constprop.6+0x1a/0x150 [50006.499872] ? irdma_sc_process_ceq+0x483/0x790 [irdma] [50006.505742] ? irdma_sc_process_ceq+0x483/0x790 [irdma] [50006.511644] kasan_report.cold.11+0x7f/0x118 [50006.516572] ? irdma_sc_process_ceq+0x483/0x790 [irdma] [50006.522473] irdma_sc_process_ceq+0x483/0x790 [irdma] [50006.528232] irdma_process_ceq+0xb2/0x400 [irdma] [50006.533601] ? irdma_hw_flush_wqes_callback+0x370/0x370 [irdma] [50006.540298] irdma_ceq_dpc+0x44/0x100 [irdma] [50006.545306] tasklet_action_common.isra.14+0x148/0x2c0 [50006.551096] __do_softirq+0x1d0/0xaf8 [50006.555396] irq_exit_rcu+0x219/0x260 [50006.559670] irq_exit+0xa/0x20 [50006.563320] smp_apic_timer_interrupt+0x1bf/0x690 [50006.568645] apic_timer_interrupt+0xf/0x20 [50006.573341] </IRQ> The issue is that a tasklet could be pending on another core racing the delete of the irq. Fix by insuring any scheduled tasklet is killed after deleting the irq.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 13.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (18)
linux/Kernel 5.14.0 - 5.15.150linux
linux/Kernel 5.16.0 - 6.1.80linux
linux/Kernel 6.2.0 - 6.6.19linux
linux/Kernel 6.7.0 - 6.7.7linux
Linux/Linux < 5.14
Linux/Linux 44d9e52977a1b90b0db1c7f8b197c218e9226520 - 0ae8ad0013978f7471f22bcf45b027393e87f5dc
Linux/Linux 44d9e52977a1b90b0db1c7f8b197c218e9226520 - 635d79aa477f9912e602feb5498bdd51fb9cb824
Linux/Linux 44d9e52977a1b90b0db1c7f8b197c218e9226520 - b2e4a5266e3d133b4c7f0e43bf40d13ce14fd1aa
Linux/Linux 44d9e52977a1b90b0db1c7f8b197c218e9226520 - bd97cea7b18a0a553773af806dfbfac27a7c4acb
Linux/Linux 44d9e52977a1b90b0db1c7f8b197c218e9226520 - c6f1ca235f68b22b3e691b2ea87ac285e5946848
... and 8 more
Published Apr 17, 2024
Tracked Since Feb 18, 2026