Executive Summary

Informations
Name CVE-2024-44958 First vendor Publication 2024-09-04
Vendor Cve Last vendor Modification 2024-10-10

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

sched/smt: Fix unbalance sched_smt_present dec/inc

I got the following warn report while doing stress test:

jump label: negative count! WARNING: CPU: 3 PID: 38 at kernel/jump_label.c:263 static_key_slow_try_dec+0x9d/0xb0 Call Trace:

__static_key_slow_dec_cpuslocked+0x16/0x70
sched_cpu_deactivate+0x26e/0x2a0
cpuhp_invoke_callback+0x3ad/0x10d0
cpuhp_thread_fun+0x3f5/0x680
smpboot_thread_fn+0x56d/0x8d0
kthread+0x309/0x400
ret_from_fork+0x41/0x70
ret_from_fork_asm+0x1b/0x30

Because when cpuset_cpu_inactive() fails in sched_cpu_deactivate(), the cpu offline failed, but sched_smt_present is decremented before calling sched_cpu_deactivate(), it leads to unbalanced dec/inc, so fix it by incrementing sched_smt_present in the error path.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44958

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3670

Sources (Detail)

https://git.kernel.org/stable/c/2a3548c7ef2e135aee40e7e5e44e7d11b893e7c4
https://git.kernel.org/stable/c/2cf7665efe451e48d27953e6b5bc627d518c902b
https://git.kernel.org/stable/c/65727331b60197b742089855ac09464c22b96f66
https://git.kernel.org/stable/c/d0c87a3c6be10a57aa3463c32c3fc6b2a47c3dab
https://git.kernel.org/stable/c/e22f910a26cc2a3ac9c66b8e935ef2a7dd881117
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
Date Informations
2025-03-29 03:39:56
  • Multiple Updates
2025-03-28 13:44:29
  • Multiple Updates
2025-03-28 03:18:09
  • Multiple Updates
2025-03-19 03:13:31
  • Multiple Updates
2025-03-18 03:26:26
  • Multiple Updates
2025-03-14 03:13:43
  • Multiple Updates
2025-03-06 14:10:15
  • Multiple Updates
2025-02-22 03:23:48
  • Multiple Updates
2025-01-08 03:04:51
  • Multiple Updates
2025-01-07 03:04:24
  • Multiple Updates
2024-12-25 03:03:02
  • Multiple Updates
2024-12-12 03:05:58
  • Multiple Updates
2024-11-23 03:02:59
  • Multiple Updates
2024-11-22 03:01:10
  • Multiple Updates
2024-11-20 02:59:30
  • Multiple Updates
2024-11-14 02:59:48
  • Multiple Updates
2024-11-09 02:59:49
  • Multiple Updates
2024-10-26 02:57:11
  • Multiple Updates
2024-10-25 02:59:04
  • Multiple Updates
2024-10-23 02:58:16
  • Multiple Updates
2024-10-10 21:27:52
  • Multiple Updates
2024-09-05 17:27:25
  • Multiple Updates
2024-09-05 00:27:26
  • First insertion