CVE-2024-26605
published 2024-02-26CVE-2024-26605: In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last minute revert in 6.7-final introduced a…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
PCI/ASPM: Fix deadlock when enabling ASPM
A last minute revert in 6.7-final introduced a potential deadlock when
enabling ASPM during probe of Qualcomm PCIe controllers as reported by
lockdep:
WARNING: possible recursive locking detected
6.7.0 #40 Not tainted
kworker/u16:5/90 is trying to acquire lock:
ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pcie_aspm_pm_state_change+0x58/0xdc
but task is already holding lock:
ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pci_walk_bus+0x34/0xbc
other info that might help us debug this:
Possible unsafe locking scenario:
CPU0
----
lock(pci_bus_sem);
lock(pci_bus_sem);
*** DEADLOCK ***
Call trace:
print_deadlock_bug+0x25c/0x348
__lock_acquire+0x10a4/0x2064
lock_acquire+0x1e8/0x318
down_read+0x60/0x184
pcie_aspm_pm_state_change+0x58/0xdc
pci_set_full_power_state+0xa8/0x114
pci_set_power_state+0xc4/0x120
qcom_pcie_enable_aspm+0x1c/0x3c [pcie_qcom]
pci_walk_bus+0x64/0xbc
qcom_pcie_host_post_init_2_7_0+0x28/0x34 [pcie_qcom]
The deadlock can easily be reproduced on machines like the Lenovo ThinkPad
X13s by adding a delay to increase the race window during asynchronous
probe where another thread can take a write lock.
Add a new pci_set_power_state_locked() and associated helper functions that
can be called with the PCI bus semaphore held to avoid taking the read lock
twice.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.90-1 (bookworm) | linux 6.1.90-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 5.15.147 < 5.16 | 5.16 |
| linux | linux | >= 6.1.72 < 6.1.88 | 6.1.88 |
| linux | linux | >= 6.6.11 < 6.6.29 | 6.6.29 |
| linux | linux | >= 8cc22ba3f77c59df5f1ac47d62df51efb28cd868 < b0f4478838be1f1d330061201898fef65bf8fd7c | b0f4478838be1f1d330061201898fef65bf8fd7c |
| linux | linux | >= b9c370b61d735a0e5390c42771e7eb21413f7868 < 0f7908a016c092cfdaa16d785fa5099d867bc1a3 | 0f7908a016c092cfdaa16d785fa5099d867bc1a3 |
| linux | linux | >= f93e71aea6c60ebff8adbd8941e678302d377869 < ef90508574d7af48420bdc5f7b9a4f1cdd26bc70 | ef90508574d7af48420bdc5f7b9a4f1cdd26bc70 |
| linux | linux | >= f93e71aea6c60ebff8adbd8941e678302d377869 < 1e560864159d002b453da42bd2c13a1805515a20 | 1e560864159d002b453da42bd2c13a1805515a20 |
| linux | linux_kernel | >= 0 < 6.1.90-1 | 6.1.90-1 |
| linux | linux_kernel | >= 0 < 6.7.7-1 | 6.7.7-1 |
| linux | linux_kernel | >= 0 < 6.7.7-1 | 6.7.7-1 |
| linux | linux_kernel | >= 6.7.0 < 6.7.5 | 6.7.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-26605: In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last minute revert in 6
osv·2024-02-26·CVSS 5.5
CVE-2024-26605 [MEDIUM] CVE-2024-26605: In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last minute revert in 6
In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last minute revert in 6.7-final introduced a potential deadlock when enabling ASPM during probe of Qualcomm PCIe controllers as reported by lockdep: ============================================ WARNING: possible recursive locking detected 6.7.0 #40 Not tainted -------------------------------------------- kworker/u16:5/90 is trying to acquire lock: ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pcie_aspm_pm_state_change+0x58/0xdc but task is already holding lock: ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pci_walk_bus+0x34/0xbc other info that might help us debug this: Possible unsafe locking scenario: CPU0 ---- lock(pci_bus_sem); lock(pci_bus_sem); *** DEADLOCK *** Call tra
GHSA
GHSA-5p3m-pw6j-5jwm: In the Linux kernel, the following vulnerability has been resolved:
PCI/ASPM: Fix deadlock when enabling ASPM
A last minute revert in 6
ghsa_unreviewed·2024-02-26
CVE-2024-26605 [MEDIUM] CWE-667 GHSA-5p3m-pw6j-5jwm: In the Linux kernel, the following vulnerability has been resolved:
PCI/ASPM: Fix deadlock when enabling ASPM
A last minute revert in 6
In the Linux kernel, the following vulnerability has been resolved:
PCI/ASPM: Fix deadlock when enabling ASPM
A last minute revert in 6.7-final introduced a potential deadlock when
enabling ASPM during probe of Qualcomm PCIe controllers as reported by
lockdep:
WARNING: possible recursive locking detected
6.7.0 #40 Not tainted
kworker/u16:5/90 is trying to acquire lock:
ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pcie_aspm_pm_state_change+0x58/0xdc
but task is already holding lock:
ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pci_walk_bus+0x34/0xbc
other info that might help us debug this:
Possible unsafe locking scenario:
CPU0
----
lock(pci_bus_sem);
lock(pci_bus_sem);
*** DEADLOCK ***
Call trace:
print_deadlock_bug+0x25c/0x348
__lock_acquire+0x10a4/0x2064
lock_acquire+0x1e8
Red Hat
kernel: PCI/ASPM: Fix deadlock when enabling ASPM
vendor_redhat·2024-02-24·CVSS 5.5
CVE-2024-26605 [MEDIUM] CWE-833 kernel: PCI/ASPM: Fix deadlock when enabling ASPM
kernel: PCI/ASPM: Fix deadlock when enabling ASPM
In the Linux kernel, the following vulnerability has been resolved:
PCI/ASPM: Fix deadlock when enabling ASPM
A last minute revert in 6.7-final introduced a potential deadlock when
enabling ASPM during probe of Qualcomm PCIe controllers as reported by
lockdep:
WARNING: possible recursive locking detected
6.7.0 #40 Not tainted
kworker/u16:5/90 is trying to acquire lock:
ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pcie_aspm_pm_state_change+0x58/0xdc
but task is already holding lock:
ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pci_walk_bus+0x34/0xbc
other info that might help us debug this:
Possible unsafe locking scenario:
CPU0
----
lock(pci_bus_sem);
lock(pci_bus_sem);
*** DEADLOCK ***
Call trace:
print_deadlock_bug+0x25c/0x348
__lo
Debian
CVE-2024-26605: linux - In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: F...
vendor_debian·2024·CVSS 5.5
CVE-2024-26605 [MEDIUM] CVE-2024-26605: linux - In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: F...
In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last minute revert in 6.7-final introduced a potential deadlock when enabling ASPM during probe of Qualcomm PCIe controllers as reported by lockdep: ============================================ WARNING: possible recursive locking detected 6.7.0 #40 Not tainted -------------------------------------------- kworker/u16:5/90 is trying to acquire lock: ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pcie_aspm_pm_state_change+0x58/0xdc but task is already holding lock: ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pci_walk_bus+0x34/0xbc other info that might help us debug this: Possible unsafe locking scenario: CPU0 ---- lock(pci_bus_sem); lock(pci_bus_sem); *** DEADLOCK *** Call tra
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0f7908a016c092cfdaa16d785fa5099d867bc1a3https://git.kernel.org/stable/c/1e560864159d002b453da42bd2c13a1805515a20https://git.kernel.org/stable/c/b0f4478838be1f1d330061201898fef65bf8fd7chttps://git.kernel.org/stable/c/ef90508574d7af48420bdc5f7b9a4f1cdd26bc70https://git.kernel.org/stable/c/0f7908a016c092cfdaa16d785fa5099d867bc1a3https://git.kernel.org/stable/c/1e560864159d002b453da42bd2c13a1805515a20https://git.kernel.org/stable/c/b0f4478838be1f1d330061201898fef65bf8fd7chttps://git.kernel.org/stable/c/ef90508574d7af48420bdc5f7b9a4f1cdd26bc70
2024-02-26
Published