cbcvebase.
CVE-2024-36944
published 2024-05-30

CVE-2024-36944: In the Linux kernel, the following vulnerability has been resolved: Reapply "drm/qxl: simplify qxl_fence_wait" This reverts commit…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
6.0th percentile
In the Linux kernel, the following vulnerability has been resolved: Reapply "drm/qxl: simplify qxl_fence_wait" This reverts commit 07ed11afb68d94eadd4ffc082b97c2331307c5ea. Stephen Rostedt reports: "I went to run my tests on my VMs and the tests hung on boot up. Unfortunately, the most I ever got out was: [ 93.607888] Testing event system initcall: OK [ 93.667730] Running tests on all trace events: [ 93.669757] Testing all events: OK [ 95.631064] ------------[ cut here ]------------ Timed out after 60 seconds" and further debugging points to a possible circular locking dependency between the console_owner locking and the worker pool locking. Reverting the commit allows Steve's VM to boot to completion again. [ This may obviously result in the "[TTM] Buffer eviction failed" messages again, which was the reason for that original revert. But at this point this seems preferable to a non-booting system... ]

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux>= 07ed11afb68d94eadd4ffc082b97c2331307c5ea < 3628e0383dd349f02f882e612ab6184e4bb3dc103628e0383dd349f02f882e612ab6184e4bb3dc10
linuxlinux>= 13ab5db42a593f9904acc39055ee3ae75963fc88 < 3dfe35d8683daf9ba69278643efbabe40000bbf63dfe35d8683daf9ba69278643efbabe40000bbf6
linuxlinux>= 42cbe04a5c77da74fb7161b0ae63f1f6e105d633 < 148ed8b4d64f94ab079c8f0d88c3f444db97ba97148ed8b4d64f94ab079c8f0d88c3f444db97ba97
linuxlinux>= 5.15.156 < 5.15.1595.15.159
linuxlinux>= 6.1.87 < 6.1.916.1.91
linuxlinux>= 6.6.28 < 6.6.316.6.31
linuxlinux>= 6.8.7 < 6.8.106.8.10
linuxlinux>= 84fb60063509e462e39c0e097c7d6dbb71c95967 < b548c53bc3ab83dc6fc86c8e840f013b2032267ab548c53bc3ab83dc6fc86c8e840f013b2032267a
linuxlinux>= 8d278fc34cdd8a44e995fa93dfd31d619a2e1fe6 < 4a89ac4b0921c4ea21eb1b4cf3a469a91bacfcea4a89ac4b0921c4ea21eb1b4cf3a469a91bacfcea
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.15.156 < 5.15.1595.15.159
linuxlinux_kernel>= 6.1.87 < 6.1.916.1.91
linuxlinux_kernel>= 6.6.28 < 6.6.316.6.31
linuxlinux_kernel>= 6.8.7 < 6.8.106.8.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_oracle9.8CRITICAL
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.