cbcvebase.
CVE-2024-36029
published 2024-05-30

CVE-2024-36029: In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-msm: pervent access to suspended controller Generic sdhci code registers LED…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-msm: pervent access to suspended controller Generic sdhci code registers LED device and uses host->runtime_suspended flag to protect access to it. The sdhci-msm driver doesn't set this flag, which causes a crash when LED is accessed while controller is runtime suspended. Fix this by setting the flag correctly.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= 67e6db113c903f2b8af924400b7b43ade4b9ac5c < 1200481cd6069d16ce20133bcd86f5825e26a0451200481cd6069d16ce20133bcd86f5825e26a045
linuxlinux>= 67e6db113c903f2b8af924400b7b43ade4b9ac5c < a957ea5aa3d3518067a1ba32c6127322ad348d20a957ea5aa3d3518067a1ba32c6127322ad348d20
linuxlinux>= 67e6db113c903f2b8af924400b7b43ade4b9ac5c < 56b99a52229d7f8cd1f53d899f57aa7eb4b199af56b99a52229d7f8cd1f53d899f57aa7eb4b199af
linuxlinux>= 67e6db113c903f2b8af924400b7b43ade4b9ac5c < f653b04a818c490b045c97834d559911479aa1c5f653b04a818c490b045c97834d559911479aa1c5
linuxlinux>= 67e6db113c903f2b8af924400b7b43ade4b9ac5c < f8def10f73a516b771051a2f70f2f0446902cb4ff8def10f73a516b771051a2f70f2f0446902cb4f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 4.10 < 5.15.1585.15.158
linuxlinux_kernel>= 5.16 < 6.1.906.1.90
linuxlinux_kernel>= 6.2 < 6.6.306.6.30
linuxlinux_kernel>= 6.7 < 6.8.96.8.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.