{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-38544",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-06-18T19:36:34.919Z",
        "datePublished": "2024-06-19T13:35:18.676Z",
        "dateUpdated": "2026-08-05T11:32:41.788Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:32:41.788Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix seg fault in rxe_comp_queue_pkt\n\nIn rxe_comp_queue_pkt() an incoming response packet skb is enqueued to the\nresp_pkts queue and then a decision is made whether to run the completer\ntask inline or schedule it. Finally the skb is dereferenced to bump a 'hw'\nperformance counter. This is wrong because if the completer task is\nalready running in a separate thread it may have already processed the skb\nand freed it which can cause a seg fault.  This has been observed\ninfrequently in testing at high scale.\n\nThis patch fixes this by changing the order of enqueuing the packet until\nafter the counter is accessed."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - The vulnerable function is reached directly from the Soft-RoCE UDP encapsulation receive handler on port 4791 (rxe_udp_encap_recv → rxe_rcv → rxe_rcv_pkt → rxe_comp_queue_pkt), processing data from a remote peer. RoCEv2 is routable IP/UDP traffic, so the attacker is not confined to the local L2 segment.\nAC:L - The attacker controls both sides of the race: the vulnerable counter access only occurs when resp_pkts already holds another packet (queue_len > 1), a condition created by bursting response packets while the completer work item concurrently drains and kfree_skb()s them on another CPU. The commit describes it triggering under high packet load, which is exactly what an attacker-driven flood produces.\nPR:N - RoCEv2 provides no authentication; the only checks before the UAF are QPN lookup, QP state, source/destination IP matching the QP's address vector, default pkey, and a plain CRC32 ICRC that any attacker can compute. A malicious or compromised RDMA peer, or an attacker spoofing the peer's source address, needs no credentials on the target system.\nUI:N - Exploitation requires only that the target have an active RC/UC queue pair in RTS state, which is the normal steady-state operating condition of an RDMA connection. No action by any local user or administrator is needed at attack time.\nS:U - The use-after-free corrupts kernel slab memory and is exploited within the kernel's own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The freed skb's control block is read after kfree_skb(), so the attacker can groom the reallocated slab object to source the rxe pointer, and a use-after-free on the skb slab is a classic primitive for leaking adjacent kernel memory and defeating KASLR.\nI:H - The stale pointer read from the freed object is immediately passed to rxe_counter_inc(), which performs atomic64_inc(&rxe->stats_counters[index]) — a write through an attacker-influenceable pointer, giving a targeted 64-bit increment primitive that can corrupt arbitrary kernel structures and be escalated to control-flow hijack.\nA:H - The commit explicitly reports a segmentation fault (kernel oops) from this dereference, and any unresolved use-after-free of an skb reliably crashes or panics the kernel, which a remote attacker can trigger repeatedly."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/infiniband/sw/rxe/rxe_comp.c"
                    ],
                    "versions": [
                        {
                            "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
                            "lessThan": "c91fb72a2ca6480d8d77262eef52dc5b178463a3",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
                            "lessThan": "de5a059e36657442b5637cc16df5163e435b9cb4",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
                            "lessThan": "e0e14dd35d4242340c7346aac60c7ff8fbf87ffc",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
                            "lessThan": "faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
                            "lessThan": "21b4c6d4d89030fd4657a8e7c8110fd941049794",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
                            "lessThan": "bbad88f111a1829f366c189aa48e7e58e57553fc",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
                            "lessThan": "30df4bef8b8e183333e9b6e9d4509d552c7da6eb",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0b1e5b99a48b5b810e3e38f1d6e0d39306b99ec0",
                            "lessThan": "2b23b6097303ed0ba5f4bc036a1c07b6027af5c6",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/infiniband/sw/rxe/rxe_comp.c"
                    ],
                    "versions": [
                        {
                            "version": "4.12",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "4.12",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.4.285",
                            "lessThanOrEqual": "5.4.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.227",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.168",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.93",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.33",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.8.12",
                            "lessThanOrEqual": "6.8.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.9.3",
                            "lessThanOrEqual": "6.9.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.10",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.12",
                                    "versionEndExcluding": "5.4.285"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.12",
                                    "versionEndExcluding": "5.10.227"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.12",
                                    "versionEndExcluding": "5.15.168"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.12",
                                    "versionEndExcluding": "6.1.93"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.12",
                                    "versionEndExcluding": "6.6.33"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.12",
                                    "versionEndExcluding": "6.8.12"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.12",
                                    "versionEndExcluding": "6.9.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.12",
                                    "versionEndExcluding": "6.10"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/c91fb72a2ca6480d8d77262eef52dc5b178463a3"
                },
                {
                    "url": "https://git.kernel.org/stable/c/de5a059e36657442b5637cc16df5163e435b9cb4"
                },
                {
                    "url": "https://git.kernel.org/stable/c/e0e14dd35d4242340c7346aac60c7ff8fbf87ffc"
                },
                {
                    "url": "https://git.kernel.org/stable/c/faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19"
                },
                {
                    "url": "https://git.kernel.org/stable/c/21b4c6d4d89030fd4657a8e7c8110fd941049794"
                },
                {
                    "url": "https://git.kernel.org/stable/c/bbad88f111a1829f366c189aa48e7e58e57553fc"
                },
                {
                    "url": "https://git.kernel.org/stable/c/30df4bef8b8e183333e9b6e9d4509d552c7da6eb"
                },
                {
                    "url": "https://git.kernel.org/stable/c/2b23b6097303ed0ba5f4bc036a1c07b6027af5c6"
                }
            ],
            "title": "RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "lang": "en",
                                "description": "CWE-noinfo Not enough information"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 6.3,
                            "attackVector": "LOCAL",
                            "baseSeverity": "MEDIUM",
                            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H",
                            "integrityImpact": "HIGH",
                            "userInteraction": "NONE",
                            "attackComplexity": "HIGH",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "LOW",
                            "confidentialityImpact": "NONE"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2024-06-20T15:44:10.125327Z",
                                "id": "CVE-2024-38544",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-11-06T16:19:22.930Z"
                }
            },
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://git.kernel.org/stable/c/faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/21b4c6d4d89030fd4657a8e7c8110fd941049794",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/bbad88f111a1829f366c189aa48e7e58e57553fc",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/30df4bef8b8e183333e9b6e9d4509d552c7da6eb",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/2b23b6097303ed0ba5f4bc036a1c07b6027af5c6",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-03T20:38:08.626Z"
                }
            }
        ]
    }
}