CVE-2024-38594
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-38594 affects the Linux kernel's network subsystem, specifically the STMicroelectronics MAC (STMMAC) driver. The vulnerability was discovered when reinitializing the EST (Enhancements for Scheduled Traffic) structure would reset the mutex lock embedded in the EST structure, triggering a kernel warning. The issue was disclosed in June 2024 and affects various Linux kernel versions (Kernel Git).

Technical details

The vulnerability occurs in the STMMAC driver's EST implementation where a mutex lock was incorrectly placed within the EST structure. When the EST structure is reinitialized, it would also reset the mutex lock, leading to potential synchronization issues. The issue manifests when the DEBUG_LOCKS_WARN_ON check triggers a warning due to an invalid lock magic value. The problem was traced to the tc_setup_taprio function where the EST structure reinitialization would corrupt the mutex lock (Kernel Git).

Impact

The vulnerability could lead to synchronization issues in the kernel's network stack, potentially affecting network traffic scheduling and timing. This could impact systems using the STMMAC driver with EST features enabled, particularly in environments requiring precise network timing control (Ubuntu Security).

Exploitability

The vulnerability requires local access to the system and the ability to interact with the network interface configuration. It primarily affects systems using the STMMAC driver with EST features. No known exploits have been reported in the wild (NVD).

Mitigation and workarounds

The issue has been fixed by moving the EST lock to the struct stmmac_priv structure. The fix involves relocating the mutex lock and properly handling lock initialization and acquisition during EST structure reinitialization. Updates are available in various Linux distributions, including Ubuntu 24.04 LTS (noble) with kernel version 6.8.0-40.40 and other affected versions (Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68454HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-xilinx-zynqmp
NoYesAug 13, 2026
CVE-2026-68452HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-zfcpdump-modules-core
NoYesAug 13, 2026
CVE-2026-68451HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-aws
NoYesAug 13, 2026
CVE-2026-68453HIGH7.1
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-modules-partner
NoYesAug 13, 2026
CVE-2026-68450NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-aws-fips
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management