CVE-2024-27435
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/05/2024
Last modified:
26/09/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
nvme: fix reconnection fail due to reserved tag allocation<br />
<br />
We found a issue on production environment while using NVMe over RDMA,<br />
admin_q reconnect failed forever while remote target and network is ok.<br />
After dig into it, we found it may caused by a ABBA deadlock due to tag<br />
allocation. In my case, the tag was hold by a keep alive request<br />
waiting inside admin_q, as we quiesced admin_q while reset ctrl, so the<br />
request maked as idle and will not process before reset success. As<br />
fabric_q shares tagset with admin_q, while reconnect remote target, we<br />
need a tag for connect command, but the only one reserved tag was held<br />
by keep alive command which waiting inside admin_q. As a result, we<br />
failed to reconnect admin_q forever. In order to fix this issue, I<br />
think we should keep two reserved tags for admin queue.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.12.1 (including) | 6.1.83 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.23 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.7.11 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.8 (including) | 6.8.2 (excluding) |
| cpe:2.3:o:linux:linux_kernel:5.12:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.12:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.12:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.12:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.12:rc7:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.12:rc8:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/149afee5c7418ec5db9d7387b9c9a5c1eb7ea2a8
- https://git.kernel.org/stable/c/262da920896e2f2ab0e3947d9dbee0aa09045818
- https://git.kernel.org/stable/c/6851778504cdb49431809b4ba061903d5f592c96
- https://git.kernel.org/stable/c/de105068fead55ed5c07ade75e9c8e7f86a00d1d
- https://git.kernel.org/stable/c/ff2f90f88d78559802466ad1c84ac5bda4416b3a
- https://git.kernel.org/stable/c/149afee5c7418ec5db9d7387b9c9a5c1eb7ea2a8
- https://git.kernel.org/stable/c/262da920896e2f2ab0e3947d9dbee0aa09045818
- https://git.kernel.org/stable/c/6851778504cdb49431809b4ba061903d5f592c96
- https://git.kernel.org/stable/c/de105068fead55ed5c07ade75e9c8e7f86a00d1d
- https://git.kernel.org/stable/c/ff2f90f88d78559802466ad1c84ac5bda4416b3a



