cbcvebase.
CVE-2024-38634
published 2024-06-21

CVE-2024-38634: In the Linux kernel, the following vulnerability has been resolved: serial: max3100: Lock port->lock when calling uart_handle_cts_change()…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved: serial: max3100: Lock port->lock when calling uart_handle_cts_change() uart_handle_cts_change() has to be called with port lock taken, Since we run it in a separate work, the lock may not be taken at the time of running. Make sure that it's taken by explicitly doing that. Without it we got a splat: WARNING: CPU: 0 PID: 10 at drivers/tty/serial/serial_core.c:3491 uart_handle_cts_change+0xa6/0xb0 ... Workqueue: max3100-0 max3100_work [max3100] RIP: 0010:uart_handle_cts_change+0xa6/0xb0 ... max3100_handlerx+0xc5/0x110 [max3100] max3100_work+0x12a/0x340 [max3100]

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 7831d56b0a3544cbb6f82f76c34ca95e24d5b676 < 44b38924135d2093e2ec1812969464845dd66dc944b38924135d2093e2ec1812969464845dd66dc9
linuxlinux>= 7831d56b0a3544cbb6f82f76c34ca95e24d5b676 < ea9b35372b58ac2931bfc1d5bc25e839d1221e30ea9b35372b58ac2931bfc1d5bc25e839d1221e30
linuxlinux>= 7831d56b0a3544cbb6f82f76c34ca95e24d5b676 < cc121e3722a0a2c8f716ef991e5425b180a5fb94cc121e3722a0a2c8f716ef991e5425b180a5fb94
linuxlinux>= 7831d56b0a3544cbb6f82f76c34ca95e24d5b676 < 78dbda51bb4241b88a52d71620f06231a341f9ba78dbda51bb4241b88a52d71620f06231a341f9ba
linuxlinux>= 7831d56b0a3544cbb6f82f76c34ca95e24d5b676 < 8296bb9e5925b6634259c5d4daee88f0cc0884ec8296bb9e5925b6634259c5d4daee88f0cc0884ec
linuxlinux>= 7831d56b0a3544cbb6f82f76c34ca95e24d5b676 < 93df2fba6c7dfa9a2f08546ea9a5ca472875845893df2fba6c7dfa9a2f08546ea9a5ca4728758458
linuxlinux>= 7831d56b0a3544cbb6f82f76c34ca95e24d5b676 < 865b30c8661924ee9145f442bf32cea549faa869865b30c8661924ee9145f442bf32cea549faa869
linuxlinux>= 7831d56b0a3544cbb6f82f76c34ca95e24d5b676 < 77ab53371a2066fdf9b895246505f5ef5a4b5d4777ab53371a2066fdf9b895246505f5ef5a4b5d47
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 2.6.31 < 4.19.3164.19.316
linuxlinux_kernel>= 4.20 < 5.4.2785.4.278
linuxlinux_kernel>= 5.11 < 5.15.1615.15.161
linuxlinux_kernel>= 5.16 < 6.1.936.1.93
linuxlinux_kernel>= 5.5 < 5.10.2195.10.219
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.9.46.9.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.