CVE-2024-38597: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: eth: sungem: remove .ndo_poll_controller to avoid deadlocks Erhard reports netpoll warnings from sungem: netpoll_send_skb_on_dev(): eth0 enabled interrupts in poll (gem_start_xmit+0x0/0x398) WARNING: CPU: 1 PID: 1 at net/core/netpoll.c:370 netpoll_send_skb+0x1fc/0x20c gem_poll_controller() disables interrupts, which may sleep. We can't sleep in netpoll, it has interrupts disabled completely. Strangely, gem_poll_controller() doesn't even poll the completions, and instead acts as if an interrupt has fired so it just schedules NAPI and exits. None of this has been necessary for years, since netpoll invokes NAPI directly.

Affected products

  • Linux Linux Kernel: from 3.1, before 5.10.219 (fixed in 5.10.219); from 5.11, before 5.15.161 (fixed in 5.15.161); from 5.16, before 6.1.93 (fixed in 6.1.93); from 6.2, before 6.6.33 (fixed in 6.6.33); from 6.7, before 6.8.12 (fixed in 6.8.12); from 6.9, before 6.9.3 (fixed in 6.9.3)

Published 2024-06-19. Last modified 2026-06-17.