cbcvebase.
CVE-2024-35953
published 2024-05-20

CVE-2024-35953: In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix deadlock in context_xa ivpu_device->context_xa is locked both in kernel…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
6.7th percentile
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix deadlock in context_xa ivpu_device->context_xa is locked both in kernel thread and IRQ context. It requires XA_FLAGS_LOCK_IRQ flag to be passed during initialization otherwise the lock could be acquired from a thread and interrupted by an IRQ that locks it for the second time causing the deadlock. This deadlock was reported by lockdep and observed in internal tests.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.8.9-1 (forky)linux 6.8.9-1 (forky)
linuxlinux
linuxlinux>= 35b137630f08d913fc2e33df33ccc2570dff3f7d < d43e11d9c7fcb16f18bd46ab2556c2772ffc5775d43e11d9c7fcb16f18bd46ab2556c2772ffc5775
linuxlinux>= 35b137630f08d913fc2e33df33ccc2570dff3f7d < e6011411147209bc0cc14628cbc155356837e52ae6011411147209bc0cc14628cbc155356837e52a
linuxlinux>= 35b137630f08d913fc2e33df33ccc2570dff3f7d < fd7726e75968b27fe98534ccbf47ccd6fef686f3fd7726e75968b27fe98534ccbf47ccd6fef686f3
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 6.3 < 6.6.286.6.28
linuxlinux_kernel>= 6.7 < 6.8.76.8.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.8MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.