cbcvebase.
CVE-2024-27009
published 2024-05-01

CVE-2024-27009: In the Linux kernel, the following vulnerability has been resolved: s390/cio: fix race condition during online processing A race condition exists in…

PriorityP418medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.18%
7.2th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/cio: fix race condition during online processing A race condition exists in ccw_device_set_online() that can cause the online process to fail, leaving the affected device in an inconsistent state. As a result, subsequent attempts to set that device online fail with return code ENODEV. The problem occurs when a path verification request arrives after a wait for final device state completed, but before the result state is evaluated. Fix this by ensuring that the CCW-device lock is held between determining final state and checking result state. Note that since: commit 2297791c92d0 ("s390/cio: dont unregister subchannel from child-drivers") path verification requests are much more likely to occur during boot, resulting in an increased chance of this race condition occurring.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= 2297791c92d04a154ad29ba5a073f9f627982110 < 3076b3c38a704e10df5e143c213653309d5325383076b3c38a704e10df5e143c213653309d532538
linuxlinux>= 2297791c92d04a154ad29ba5a073f9f627982110 < 559f3a6333397ab6cd4a696edd65a70b6be62c6e559f3a6333397ab6cd4a696edd65a70b6be62c6e
linuxlinux>= 2297791c92d04a154ad29ba5a073f9f627982110 < 2df56f4ea769ff81e51bbb05699989603bde9c492df56f4ea769ff81e51bbb05699989603bde9c49
linuxlinux>= 2297791c92d04a154ad29ba5a073f9f627982110 < a4234decd0fe429832ca81c4637be7248b88b49ea4234decd0fe429832ca81c4637be7248b88b49e
linuxlinux>= 2297791c92d04a154ad29ba5a073f9f627982110 < 2d8527f2f911fab84aec04df4788c0c23af3df482d8527f2f911fab84aec04df4788c0c23af3df48
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 5.15 < 5.15.1575.15.157
linuxlinux_kernel>= 5.16 < 6.1.886.1.88
linuxlinux_kernel>= 6.2 < 6.6.296.6.29
linuxlinux_kernel>= 6.7 < 6.8.86.8.8
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.8MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.