CVE-2024-38598

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/06/2024
Last modified:
12/05/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> md: fix resync softlockup when bitmap size is less than array size<br /> <br /> Is is reported that for dm-raid10, lvextend + lvchange --syncaction will<br /> trigger following softlockup:<br /> <br /> kernel:watchdog: BUG: soft lockup - CPU#3 stuck for 26s! [mdX_resync:6976]<br /> CPU: 7 PID: 3588 Comm: mdX_resync Kdump: loaded Not tainted 6.9.0-rc4-next-20240419 #1<br /> RIP: 0010:_raw_spin_unlock_irq+0x13/0x30<br /> Call Trace:<br /> <br /> md_bitmap_start_sync+0x6b/0xf0<br /> raid10_sync_request+0x25c/0x1b40 [raid10]<br /> md_do_sync+0x64b/0x1020<br /> md_thread+0xa7/0x170<br /> kthread+0xcf/0x100<br /> ret_from_fork+0x30/0x50<br /> ret_from_fork_asm+0x1a/0x30<br /> <br /> And the detailed process is as follows:<br /> <br /> md_do_sync<br /> j = mddev-&gt;resync_min<br /> while (j

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.19.291 (including) 4.19.316 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.4.251 (including) 5.4.278 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.10.188 (including) 5.10.219 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15.121 (including) 5.15.161 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.39 (including) 6.1.93 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.5 (including) 6.6.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.8.12 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.9 (including) 6.9.3 (excluding)


References to Advisories, Solutions, and Tools