Linux Kernel Hinic Bond Slave Device Statistics Handling Vulnerability Leading to Kernel Hang

Vulnerability

A vulnerability in the Linux kernel's handling of statistics for Hinic devices used as bond slaves can cause the kernel to hang. This issue arises when device statistics are read from the master bond device, leading to a soft lockup and kernel panic. The problem occurs because the Hinic statistics retrieval function, hinic_get_stats64(), improperly manages locks, causing tasks to be scheduled out and potentially left hanging, especially under high system load.

Impact

Exploitation of this vulnerability can lead to a kernel hang, causing a soft lockup and a subsequent kernel panic.

Added: Jun 18, 2025, 2:49 PM
Updated: Jun 18, 2025, 2:49 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
7.7
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.