CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-50157: RDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop

Description

In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop

Driver waits indefinitely for the fifo occupancy to go below a threshold
as soon as the pacing interrupt is received. This can cause soft lockup on
one of the processors, if the rate of DB is very high.

Add a loop count for FPGA and exit the __wait_for_fifo_occupancy_below_th
if the loop is taking more time. Pacing will be continuing until the
occupancy is below the threshold. This is ensured by the checks in
bnxt_re_pacing_timer_exp and further scheduling the work for pacing based
on the fifo occupancy.

Classification

CVE ID: CVE-2024-50157

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 5.0% (scored less or equal to compared to others)

EPSS Date: 2025-03-03 (when was this score calculated)

References

https://git.kernel.org/stable/c/7998e7efd1d557af118ac96f48ebc569b929b555
https://git.kernel.org/stable/c/2fb6b2e82413e401b72dfeacd7a60416fcfc5b41
https://git.kernel.org/stable/c/8be3e5b0c96beeefe9d5486b96575d104d3e7d17

Timeline