CVE-2024-36908Improper Input Validation in Linux

Severity
5.5MEDIUMNVD
OSV8.8OSV6.5
EPSS
0.0%
top 99.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 30
Latest updateSep 2

Description

In the Linux kernel, the following vulnerability has been resolved: blk-iocost: do not WARN if iocg was already offlined In iocg_pay_debt(), warn is triggered if 'active_list' is empty, which is intended to confirm iocg is active when it has debt. However, warn can be triggered during a blkcg or disk removal, if iocg_waitq_timer_fn() is run at that time: WARNING: CPU: 0 PID: 2344971 at block/blk-iocost.c:1402 iocg_pay_debt+0x14c/0x190 Call trace: iocg_pay_debt+0x14c/0x190 iocg_kick_waitq+0x43

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDlinux/linux_kernel5.45.10.237+5
Debianlinux/linux_kernel< 5.10.237-1+3
Ubuntulinux/linux_kernel< 5.15.0-144.157+1
CVEListV5linux/linux7caa47151ab2e644dd221f741ec7578d9532c9a356a9d07f427378eeb75b917bb49c6fbea8204126+6
debiandebian/linux< linux 6.1.135-1 (bookworm)

Patches

🔴Vulnerability Details

16
OSV
linux-azure-5.15 vulnerabilities2025-09-02
OSV
linux-azure-fips vulnerabilities2025-08-22
OSV
linux-azure vulnerabilities2025-08-22
OSV
linux-raspi vulnerabilities2025-08-05
OSV
linux-xilinx-zynqmp vulnerabilities2025-07-29

📋Vendor Advisories

16
Ubuntu
Linux kernel (Azure) vulnerabilities2025-09-02
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2025-08-22
Ubuntu
Linux kernel (Azure) vulnerabilities2025-08-22
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-08-05
Ubuntu
Linux kernel (Xilinx ZynqMP) vulnerabilities2025-07-29

💬Community

1
Bugzilla
CVE-2024-36908 kernel: blk-iocost: do not WARN if iocg was already offlined2024-06-03