cbcvebase.
CVE-2024-27072
published 2024-05-01

CVE-2024-27072: In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Remove useless locks in usbtv_video_free() Remove locks calls in…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.8th percentile
In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Remove useless locks in usbtv_video_free() Remove locks calls in usbtv_video_free() because are useless and may led to a deadlock as reported here: https://syzkaller.appspot.com/x/bisect.txt?x=166dc872180000 Also remove usbtv_stop() call since it will be called when unregistering the device. Before 'c838530d230b' this issue would only be noticed if you disconnect while streaming and now it is noticeable even when disconnecting while not streaming. [hverkuil: fix minor spelling mistake in log message]

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= f3d27f34fdd7701e499617d2c1d94480a98f6d07 < 4ec4641df57cbdfdc51bb4959afcdbcf5003ddb94ec4641df57cbdfdc51bb4959afcdbcf5003ddb9
linuxlinux>= f3d27f34fdd7701e499617d2c1d94480a98f6d07 < d5ed208d04acf06781d63d30f9fa991e8d609ebdd5ed208d04acf06781d63d30f9fa991e8d609ebd
linuxlinux>= f3d27f34fdd7701e499617d2c1d94480a98f6d07 < bdd82c47b22a8befd617b723098b2a41b77373c7bdd82c47b22a8befd617b723098b2a41b77373c7
linuxlinux>= f3d27f34fdd7701e499617d2c1d94480a98f6d07 < dea46e246ef0f98d89d59a4229157cd9ffb636bfdea46e246ef0f98d89d59a4229157cd9ffb636bf
linuxlinux>= f3d27f34fdd7701e499617d2c1d94480a98f6d07 < 3e7d82ebb86e94643bdb30b0b5b077ed27dce1c23e7d82ebb86e94643bdb30b0b5b077ed27dce1c2
linuxlinux>= f3d27f34fdd7701e499617d2c1d94480a98f6d07 < 65e6a2773d655172143cc0b927cdc8954984289565e6a2773d655172143cc0b927cdc89549842895
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 3.11 < 5.10.2275.10.227
linuxlinux_kernel>= 5.11 < 5.15.1685.15.168
linuxlinux_kernel>= 5.16 < 6.1.1136.1.113
linuxlinux_kernel>= 6.2 < 6.6.556.6.55
linuxlinux_kernel>= 6.7 < 6.8.26.8.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.