CVE-2024-52332 affects the Linux kernel's Intel igb Ethernet driver. When pci_register_driver() fails during igb_init_module(), the driver could leave dca_notifier registered; a subsequent notifier call could then access invalid memory after the driver installation has failed. The defect, present since kernel version 2.6.29, can cause a local denial of service. Upstream fixes are available in stable kernels 5.4.287, 5.10.231, 5.15.174, 6.1.120, 6.6.66, 6.12.5, and 6.13-rc2.
Red Hat rated the flaw Moderate with CVSS 4.7, citing required local access, low privileges, high attack complexity, and high availability impact. Fixes were issued for standard kernels in RHEL 9 and RHEL 10 through RHSA-2025:20518 and RHSA-2025:20095; RHEL 10 kernel-rt remains affected, while RHEL 9 kernel-rt is marked will not fix. Organizations should update to a current vendor-supported kernel release rather than backporting the isolated patch; where patching is not immediately feasible, Red Hat recommends preventing the igb module from loading, including by blacklisting it when operationally viable.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:20518 for the RHEL 9 standard kernel and RHSA-2025:20095 for the RHEL 10 standard kernel to address CVE-2024-52332. RHEL 10 kernel-rt remained affected without an identified erratum, while RHEL 9 kernel-rt was marked will not fix.
The Linux kernel CVE team published an advisory for CVE-2024-52332, documenting the Intel igb driver flaw and fixes in stable kernel versions 5.4.287, 5.10.231, 5.15.174, 6.1.120, 6.6.66, 6.12.5, and 6.13-rc2.
A change in Linux kernel version 2.6.29 introduced an error-path flaw in the Intel igb driver's igb_init_module() function: dca_notifier was not unregistered if pci_register_driver() failed, potentially enabling invalid memory access on a later notifier call.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.