PT-2024-26840 · Linux+7 · Linux Kernel+7

Published

2024-04-23

·

Updated

2026-05-26

·

CVE-2024-36003

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description A vulnerability has been resolved in the Linux kernel, specifically in the ice driver. The issue is related to a potential deadlock situation that can occur when the ice reset vf() function acquires the LAG mutex and then the VF configuration lock, while another function, ice vc cfg qs msg(), acquires the locks in a different order. This can lead to a circular locking dependency, causing a deadlock. The vulnerability is detected by Lockdep, a kernel feature that detects potential locking issues.
Recommendations To resolve this issue, update the Linux kernel to version 6.6.37 or later. This version includes the fix for the deadlock situation in the ice driver. If updating the kernel is not possible, consider disabling the ice driver or restricting its use to minimize the risk of exploitation. However, these workarounds are not recommended as they may have significant performance implications. The best course of action is to update the kernel to the latest version.

Exploit

Fix

DoS

Improper Locking

Weakness Enumeration

Related Identifiers

ALSA-2024:5928
ALSA-2025_16880
BDU:2025-03063
CVE-2024-36003
INFSA-2024_5928
MGASA-2024-0263
MGASA-2024-0266
RHSA-2024:5928
RHSA-2024_5928
SUSE-SU-2024:2802-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu