CVE-2024-27030
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-27030 affects the Linux kernel's octeontx2-af driver, where a race condition vulnerability was discovered. The issue exists because the same interrupt handler is registered for both PF to AF interrupt vector and VF to AF vector. The vulnerability was discovered on May 1, 2024, and affects Linux kernel versions from 4.20 up to versions before 5.4.273, 5.10.214, 5.15.153, and 6.1.83 (NVD).

Technical details

The vulnerability stems from a race condition in the interrupt handling mechanism of the octeontx2-af driver. When two interrupts are raised to two CPUs simultaneously, two cores serve the same event, leading to data corruption. The issue has been assigned a CVSS v3.1 base score of 6.3 (Medium), with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H, indicating local access required with high attack complexity (NVD).

Impact

The vulnerability can result in data corruption when multiple CPUs handle interrupts simultaneously. This occurs specifically when two interrupts are raised to two CPUs at the same time, causing both cores to service the same event and potentially corrupting the data in the process (Kernel Patch).

Exploitability

The vulnerability requires local access and high attack complexity to exploit. An attacker would need to have local access to the system and the ability to trigger simultaneous interrupts to multiple CPUs to potentially cause data corruption (NVD).

Mitigation and workarounds

The vulnerability has been fixed by implementing separate handlers for interrupts. The fix involves creating a dedicated handler for PF interrupts (rvu_mbox_pf_intr_handler) and maintaining the existing handler for VF interrupts. This separation prevents the race condition that was causing data corruption (Kernel Patch).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux: 6.1.85-1

Fixed

bullseye

linux: 5.10.216-1

Fixed

sid

linux: 6.7.12-1

Fixed

trixie

linux: 6.7.12-1

Fixed

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-oracle-5.4
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-gcp-fips
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-oracle
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management