CVE-2024-36020 - CVE House
Back to Database
Status published Unknown CVE-2024-36020

i40e: fix vf may be used uninitialized in this function warning

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: i40e: fix vf may be used uninitialized in this function warning To fix the regression introduced by commit 52424f974bc5, which causes servers hang in very hard to reproduce conditions with resets races. Using two sources for the information is the root cause. In this function before the fix bumping v didn't mean bumping vf pointer. But the code used this variables interchangeably, so stale vf could point to different/not intended vf. Remove redundant "v" variable and iterate via single VF pointer across whole function instead to guarantee VF pointer validity.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-36020

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
76ed715836c6994bac29d9638e9314e6e3b08651, e88c2a1e28c5475065563d66c07ca879a9afbd07, 9abae363af5ced6adbf04c14366289540281fb26, c39de3ae5075ea5f78e097cb5720d4e52d5caed9, 52424f974bc53c26ba3f00300a00e9de9afcd972, 02f949747e6fb767b29f7931d4bbf40911684e7a, 4.19.264, 5.4.223, 5.10.153, 5.15.77, 6.0.7, 6.1, 0, 4.19.312, 5.4.274, 5.10.215, 5.15.154, 6.1.85, 6.6.26, 6.8.5, 6.9

Timeline

Official Publish: May 30th, 2024
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.