Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-53121— net/mlx5: fs, lock FTE when checking if active

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于net/mlx5组件中FTE的活跃标志在删除过程中未被锁定检查,导致fs_core层在FTE被删除过程中附加新的转向规则,引发恐慌。

CVSS 7.8 · High EPSS 0.21% · P10

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 718ce4d601dbf73b5dbe024a88c9e34168fe87f2< 0d568258f99f2076ab02e9234cbabbd43e12f30e affected
718ce4d601dbf73b5dbe024a88c9e34168fe87f2< a508c74ceae2f5a4647f67c362126516d6404ed9 affected
718ce4d601dbf73b5dbe024a88c9e34168fe87f2< 5b47c2f47c2fe921681f4a4fe2790375e6c04cdd affected
718ce4d601dbf73b5dbe024a88c9e34168fe87f2< bfba288f53192db08c68d4c568db9783fb9cb838 affected
718ce4d601dbf73b5dbe024a88c9e34168fe87f2< 094d1a2121cee1e85ab07d74388f94809dcfb5b9 affected
718ce4d601dbf73b5dbe024a88c9e34168fe87f2< 933ef0d17f012b653e9e6006e3f50c8d0238b5ed affected
718ce4d601dbf73b5dbe024a88c9e34168fe87f2< 9ca314419930f9135727e39d77e66262d5f7bef6 affected
5.1 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-53121

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net/mlx5: fs, lock FTE when checking if active
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, lock FTE when checking if active The referenced commits introduced a two-step process for deleting FTEs: - Lock the FTE, delete it from hardware, set the hardware deletion function to NULL and unlock the FTE. - Lock the parent flow group, delete the software copy of the FTE, and remove it from the xarray. However, this approach encounters a race condition if a rule with the same match value is added simultaneously. In this scenario, fs_core may set the hardware deletion function to NULL prematurely, causing a panic during subsequent rule deletions. To prevent this, ensure the active flag of the FTE is checked under a lock, which will prevent the fs_core layer from attaching a new steering rule to an FTE that is in the process of deletion. [ 438.967589] MOSHE: 2496 mlx5_del_flow_rules del_hw_func [ 438.968205] ------------[ cut here ]------------ [ 438.968654] refcount_t: decrement hit 0; leaking memory. [ 438.969249] WARNING: CPU: 0 PID: 8957 at lib/refcount.c:31 refcount_warn_saturate+0xfb/0x110 [ 438.970054] Modules linked in: act_mirred cls_flower act_gact sch_ingress openvswitch nsh mlx5_vdpa vringh vhost_iotlb vdpa mlx5_ib mlx5_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm ib_uverbs ib_core zram zsmalloc fuse [last unloaded: cls_flower] [ 438.973288] CPU: 0 UID: 0 PID: 8957 Comm: tc Not tainted 6.12.0-rc1+ #8 [ 438.973888] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 [ 438.974874] RIP: 0010:refcount_warn_saturate+0xfb/0x110 [ 438.975363] Code: 40 66 3b 82 c6 05 16 e9 4d 01 01 e8 1f 7c a0 ff 0f 0b c3 cc cc cc cc 48 c7 c7 10 66 3b 82 c6 05 fd e8 4d 01 01 e8 05 7c a0 ff <0f> 0b c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 90 [ 438.976947] RSP: 0018:ffff888124a53610 EFLAGS: 00010286 [ 438.977446] RAX: 0000000000000000 RBX: ffff888119d56de0 RCX: 0000000000000000 [ 438.978090] RDX: ffff88852c828700 RSI: ffff88852c81b3c0 RDI: ffff88852c81b3c0 [ 438.978721] RBP: ffff888120fa0e88 R08: 0000000000000000 R09: ffff888124a534b0 [ 438.979353] R10: 0000000000000001 R11: 0000000000000001 R12: ffff888119d56de0 [ 438.979979] R13: ffff888120fa0ec0 R14: ffff888120fa0ee8 R15: ffff888119d56de0 [ 438.980607] FS: 00007fe6dcc0f800(0000) GS:ffff88852c800000(0000) knlGS:0000000000000000 [ 438.983984] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 438.984544] CR2: 00000000004275e0 CR3: 0000000186982001 CR4: 0000000000372eb0 [ 438.985205] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 438.985842] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 438.986507] Call Trace: [ 438.986799] <TASK> [ 438.987070] ? __warn+0x7d/0x110 [ 438.987426] ? refcount_warn_saturate+0xfb/0x110 [ 438.987877] ? report_bug+0x17d/0x190 [ 438.988261] ? prb_read_valid+0x17/0x20 [ 438.988659] ? handle_bug+0x53/0x90 [ 438.989054] ? exc_invalid_op+0x14/0x70 [ 438.989458] ? asm_exc_invalid_op+0x16/0x20 [ 438.989883] ? refcount_warn_saturate+0xfb/0x110 [ 438.990348] mlx5_del_flow_rules+0x2f7/0x340 [mlx5_core] [ 438.990932] __mlx5_eswitch_del_rule+0x49/0x170 [mlx5_core] [ 438.991519] ? mlx5_lag_is_sriov+0x3c/0x50 [mlx5_core] [ 438.992054] ? xas_load+0x9/0xb0 [ 438.992407] mlx5e_tc_rule_unoffload+0x45/0xe0 [mlx5_core] [ 438.993037] mlx5e_tc_del_fdb_flow+0x2a6/0x2e0 [mlx5_core] [ 438.993623] mlx5e_flow_put+0x29/0x60 [mlx5_core] [ 438.994161] mlx5e_delete_flower+0x261/0x390 [mlx5_core] [ 438.994728] tc_setup_cb_destroy+0xb9/0x190 [ 438.995150] fl_hw_destroy_filter+0x94/0xc0 [cls_flower] [ 438.995650] fl_change+0x11a4/0x13c0 [cls_flower] [ 438.996105] tc_new_tfilter+0x347/0xbc0 [ 438.996503] ? __ ---truncated---
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于net/mlx5组件中FTE的活跃标志在删除过程中未被锁定检查,导致fs_core层在FTE被删除过程中附加新的转向规则,引发恐慌。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 718ce4d601dbf73b5dbe024a88c9e34168fe87f2 ~ 0d568258f99f2076ab02e9234cbabbd43e12f30e -
Linux Linux 5.1 -

II. Public POCs for CVE-2024-53121

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-53121

登录查看更多情报信息。

Patches & Fixes for CVE-2024-53121 (7)

Same Patch Batch · Linux · 2024-12-02 · 22 CVEs total

CVE-2024-53103 7.8 HIGH hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer
CVE-2024-53107 7.8 HIGH fs/proc/task_mmu: prevent integer overflow in pagemap_scan_get_args()
CVE-2024-53109 7.8 HIGH nommu: pass NULL argument to vma_iter_prealloc()
CVE-2024-53122 7.5 HIGH mptcp: cope racing subflow creation in mptcp_rcv_space_adjust
CVE-2024-53120 7.5 HIGH net/mlx5e: CT: Fix null-ptr-deref in add rule err flow
CVE-2024-53124 7.5 HIGH net: fix data-races around sk->sk_forward_alloc
CVE-2024-53106 7.3 HIGH ima: fix buffer overrun in ima_eventdigest_init_common
CVE-2024-53108 7.3 HIGH drm/amd/display: Adjust VSDB parser for replay feature
CVE-2024-53110 7.3 HIGH vp_vdpa: fix id_table array not null terminated error
CVE-2024-53111 7.1 HIGH mm/mremap: fix address wraparound in move_page_tables()
CVE-2024-53113 mm: fix NULL pointer dereference in alloc_pages_bulk_noprof
CVE-2024-53104 media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
CVE-2024-53105 mm: page_alloc: move mlocked flag clearance into free_pages_prepare()
CVE-2024-53112 ocfs2: uncache inode which has failed entering the group
CVE-2024-53114 x86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client
CVE-2024-53115 drm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle
CVE-2024-53116 drm/panthor: Fix handling of partial GPU mapping of BOs
CVE-2024-53117 virtio/vsock: Improve MSG_ZEROCOPY error handling
CVE-2024-53119 virtio/vsock: Fix accept_queue memory leak
CVE-2024-53118 vsock: Fix sk_error_queue memory leak

Showing top 20 of 22 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-53121

No comments yet


Leave a comment