CVE-2024-26690

    Dashboard / Vulnerabilities / CVE-2024-26690

    CVE-2024-26690

    Published: 3 Apr 2024Last Modified: 8 Oct 2026

    Summary: net: stmmac: protect updates of 64-bit statistics counters

    Details: In the Linux kernel, the following vulnerability has been resolved: net: stmmac: protect updates of 64-bit statistics counters As explained by a comment in <linux/u64_stats_sync.h>, write side of struct u64_stats_sync must ensure mutual exclusion, or one seqcount update could be lost on 32-bit platforms, thus blocking readers forever. Such lockups have been observed in real world after stmmac_xmit() on one CPU raced with stmmac_napi_poll_tx() on another CPU. To fix the issue without introducing a new lock, split the statics into three parts: 1. fields updated only under the tx queue lock, 2. fields updated only during NAPI poll, 3. fields updated only from interrupt context, Updates to fields in the first two groups are already serialized through other locks. It is sufficient to split the existing struct u64_stats_sync so that each group has its own. Note that tx_set_ic_bit is updated from both contexts. Split this counter so that each context gets its own, and calculate their sum to get the total value in stmmac_get_ethtool_stats(). For the third group, multiple interrupts may be processed by different CPUs at the same time, but interrupts on the same CPU will not nest. Move fields from this group to a newly created per-cpu struct stmmac_pcpu_stats.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 133466c3bbe171f826294161db203f7670bb30c8

    Affected versions

    v6.1.189
    v6.1.188
    v6.1.187
    v6.1.186
    v6.1.185
    v6.1.184
    v6.1.183
    v6.1.182
    v6.1.181
    v6.1.180
    v6.1.179
    v6.1.178
    v6.1.177
    v6.1.176
    v6.1.175
    v6.1.174
    v6.1.173
    v6.1.172
    v6.1.171
    v6.1.170
    v6.1.169
    v6.1.168
    v6.1.167
    v6.1.166
    v6.1.165
    v6.1.164
    v6.1.163
    v6.1.162
    v6.1.161
    v6.1.160

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-26690 | CVE-DB