CVE-2024-38593

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/06/2024
Last modified:
20/10/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: micrel: Fix receiving the timestamp in the frame for lan8841<br /> <br /> The blamed commit started to use the ptp workqueue to get the second<br /> part of the timestamp. And when the port was set down, then this<br /> workqueue is stopped. But if the config option NETWORK_PHY_TIMESTAMPING<br /> is not enabled, then the ptp_clock is not initialized so then it would<br /> crash when it would try to access the delayed work.<br /> So then basically by setting up and then down the port, it would crash.<br /> The fix consists in checking if the ptp_clock is initialized and only<br /> then cancel the delayed work.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.5 (including) 6.6.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.8.12 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.9 (including) 6.9.3 (excluding)