cbcvebase.
CVE-2024-38780
published 2024-06-21

CVE-2024-38780: In the Linux kernel, the following vulnerability has been resolved: dma-buf/sw-sync: don't enable IRQ from sync_print_obj() Since commit a6aa8fca4d79…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.7th percentile
In the Linux kernel, the following vulnerability has been resolved: dma-buf/sw-sync: don't enable IRQ from sync_print_obj() Since commit a6aa8fca4d79 ("dma-buf/sw-sync: Reduce irqsave/irqrestore from known context") by error replaced spin_unlock_irqrestore() with spin_unlock_irq() for both sync_debugfs_show() and sync_print_obj() despite sync_print_obj() is called from sync_debugfs_show(), lockdep complains inconsistent lock state warning. Use plain spin_{lock,unlock}() for sync_print_obj(), for sync_debugfs_show() is already using spin_{lock,unlock}_irq().

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 4.9.68 < 4.104.10
linuxlinux>= a6aa8fca4d792c72947e341d7842d2f700534335 < 1ff116f68560a25656933d5a18e7619cb6773d8a1ff116f68560a25656933d5a18e7619cb6773d8a
linuxlinux>= a6aa8fca4d792c72947e341d7842d2f700534335 < 165b25e3ee9333f7b04f8db43895beacb51582ed165b25e3ee9333f7b04f8db43895beacb51582ed
linuxlinux>= a6aa8fca4d792c72947e341d7842d2f700534335 < ae6fc4e6a3322f6d1c8ff59150d8469487a73dd8ae6fc4e6a3322f6d1c8ff59150d8469487a73dd8
linuxlinux>= a6aa8fca4d792c72947e341d7842d2f700534335 < 9d75fab2c14a25553a1664586ed122c316bd18789d75fab2c14a25553a1664586ed122c316bd1878
linuxlinux>= a6aa8fca4d792c72947e341d7842d2f700534335 < 242b30466879e6defa521573c27e12018276c33a242b30466879e6defa521573c27e12018276c33a
linuxlinux>= a6aa8fca4d792c72947e341d7842d2f700534335 < a4ee78244445ab73af22bfc5a5fc543963b25aefa4ee78244445ab73af22bfc5a5fc543963b25aef
linuxlinux>= a6aa8fca4d792c72947e341d7842d2f700534335 < 8a283cdfc8beeb14024387a925247b563d614e1e8a283cdfc8beeb14024387a925247b563d614e1e
linuxlinux>= a6aa8fca4d792c72947e341d7842d2f700534335 < b794918961516f667b0c745aebdfebbb8a98df39b794918961516f667b0c745aebdfebbb8a98df39
linuxlinux_kernel< 4.144.14
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 4.19 < 4.19.3164.19.316
linuxlinux_kernel>= 5.10 < 5.10.2195.10.219
linuxlinux_kernel>= 5.15 < 5.15.1615.15.161
linuxlinux_kernel>= 5.4 < 5.4.2785.4.278

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.