Answer in brief
CVE-2024-38556 records a Unknown severity vulnerability in net/mlx5: Add a timeout to acquire the command queue semaphore. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8e715cd613a1e872b9d918e912d90b399785761a <4baae687a20ef2b82fde12de3c04461e6f2521d6 || >=8e715cd613a1e872b9d918e912d90b399785761a <f9caccdd42e999b74303c9b0643300073ed5d319 || >=8e715cd613a1e872b9d918e912d90b399785761a <2d0962d05c93de391ce85f6e764df895f47c8918 || >=8e715cd613a1e872b9d918e912d90b399785761a <94024332a129c6e4275569d85c0c1bfb2ae2d71b || >=8e715cd613a1e872b9d918e912d90b399785761a <485d65e1357123a697c591a5aeb773994b247ad7 || 74dd45122b84479eee50bd0956ae8bc5799c9f8a || e801f81cee3c8901f52ee48c6329802b28fbb49c || d73d81447c6651904dd4a9e3fd88651ff174c1b7 || 4646175c19fd019b773444a11ff62748eb83745b || >=5.4.174 <5.5 || >=5.10.94 <5.11 || >=5.15.17 <5.16 || >=5.16.3 <5.17 | 4baae687a20ef2b82fde12de3c04461e6f2521d6, f9caccdd42e999b74303c9b0643300073ed5d319, 2d0962d05c93de391ce85f6e764df895f47c8918, 94024332a129c6e4275569d85c0c1bfb2ae2d71b, 485d65e1357123a697c591a5aeb773994b247ad7, 5.5, 5.11, 5.16, 5.17 |
| Linux/Linuxgeneric | 5.17 | Not reported |
Published upstream
Jun 19, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Add a timeout to acquire the command queue semaphore Prevent forced completion handling on an entry that has not yet been assigned an index, causing an out of bounds access on idx = -22. Instead of waiting indefinitely for the sem, blocking flow now waits for index to be allocated or a sem acquisition timeout before beginning the timer for FW completion. Kernel log example: mlx5_core 0000:06:00.0: wait_func_handle_exec_timeout:1128:(pid 185911): cmd[-22]: CREATE_UCTX(0xa04) No done completion
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-38556 records a Unknown severity vulnerability in net/mlx5: Add a timeout to acquire the command queue semaphore. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8e715cd613a1e872b9d918e912d90b399785761a <4baae687a20ef2b82fde12de3c04461e6f2521d6 || >=8e715cd613a1e872b9d918e912d90b399785761a <f9caccdd42e999b74303c9b0643300073ed5d319 || >=8e715cd613a1e872b9d918e912d90b399785761a <2d0962d05c93de391ce85f6e764df895f47c8918 || >=8e715cd613a1e872b9d918e912d90b399785761a <94024332a129c6e4275569d85c0c1bfb2ae2d71b || >=8e715cd613a1e872b9d918e912d90b399785761a <485d65e1357123a697c591a5aeb773994b247ad7 || 74dd45122b84479eee50bd0956ae8bc5799c9f8a || e801f81cee3c8901f52ee48c6329802b28fbb49c || d73d81447c6651904dd4a9e3fd88651ff174c1b7 || 4646175c19fd019b773444a11ff62748eb83745b || >=5.4.174 <5.5 || >=5.10.94 <5.11 || >=5.15.17 <5.16 || >=5.16.3 <5.17 | 4baae687a20ef2b82fde12de3c04461e6f2521d6, f9caccdd42e999b74303c9b0643300073ed5d319, 2d0962d05c93de391ce85f6e764df895f47c8918, 94024332a129c6e4275569d85c0c1bfb2ae2d71b, 485d65e1357123a697c591a5aeb773994b247ad7, 5.5, 5.11, 5.16, 5.17 |
| Linux/Linuxgeneric | 5.17 | Not reported |
Published upstream
Jun 19, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Add a timeout to acquire the command queue semaphore Prevent forced completion handling on an entry that has not yet been assigned an index, causing an out of bounds access on idx = -22. Instead of waiting indefinitely for the sem, blocking flow now waits for index to be allocated or a sem acquisition timeout before beginning the timer for FW completion. Kernel log example: mlx5_core 0000:06:00.0: wait_func_handle_exec_timeout:1128:(pid 185911): cmd[-22]: CREATE_UCTX(0xa04) No done completion
Quoted source text, attributed separately from HOL analysis.