CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2024-46678: bonding: change ipsec_lock from spin lock to mutex

mediumCVSS 5.5CVE-2024-46678

CSIRTS triage

What
The bonding driver uses a spin lock for ipsec_lock when a mutex is required for safe operation.
Who is affected
Linux systems with bonding driver in use for network interface aggregation.
Urgency
Medium severity (CVSS 5.5) with potential for deadlock or synchronization issues.
Action
Apply the Linux kernel patch that converts ipsec_lock from spin lock to mutex.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Bonding

Get an email when a new Bonding advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 5.5
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-46678

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2024-46678coverage & exploitation statusNVD · CVE.org

Recent advisories for bonding

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Microsoft Security Response Center