cbcvebase.
CVE-2024-40976
published 2024-07-12

CVE-2024-40976: In the Linux kernel, the following vulnerability has been resolved: drm/lima: mask irqs in timeout path before hard reset There is a race condition in which a…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.5th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/lima: mask irqs in timeout path before hard reset There is a race condition in which a rendering job might take just long enough to trigger the drm sched job timeout handler but also still complete before the hard reset is done by the timeout handler. This runs into race conditions not expected by the timeout handler. In some very specific cases it currently may result in a refcount imbalance on lima_pm_idle, with a stack dump such as: [10136.669170] WARNING: CPU: 0 PID: 0 at drivers/gpu/drm/lima/lima_devfreq.c:205 lima_devfreq_record_idle+0xa0/0xb0 ... [10136.669459] pc : lima_devfreq_record_idle+0xa0/0xb0 ... [10136.669628] Call trace: [10136.669634] lima_devfreq_record_idle+0xa0/0xb0 [10136.669646] lima_sched_pipe_task_done+0x5c/0xb0 [10136.669656] lima_gp_irq_handler+0xa8/0x120 [10136.669666] __handle_irq_event_percpu+0x48/0x160 [10136.669679] handle_irq_event+0x4c/0xc0 We can prevent that race condition entirely by masking the irqs at the beginning of the timeout handler, at which point we give up on waiting for that job entirely. The irqs will be enabled again at the next hard reset which is already done as a recovery by the timeout handler.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < 03e7b2f7ae4c0ae5fb8e4e2454ba4008877f196a03e7b2f7ae4c0ae5fb8e4e2454ba4008877f196a
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < 70aa1f2dec46b6fdb5f6b9f37b6bfa4a4dee0d3a70aa1f2dec46b6fdb5f6b9f37b6bfa4a4dee0d3a
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < 9fd8ddd23793a50dbcd11c6ba51f437f1ea7d3449fd8ddd23793a50dbcd11c6ba51f437f1ea7d344
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < bdbc4ca77f5eaac15de7230814253cddfed273b1bdbc4ca77f5eaac15de7230814253cddfed273b1
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < 58bfd311c93d66d8282bf21ebbf35cc3bb8ad9db58bfd311c93d66d8282bf21ebbf35cc3bb8ad9db
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < a421cc7a6a001b70415aa4f66024fa6178885a14a421cc7a6a001b70415aa4f66024fa6178885a14
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.966.1.96
linuxlinux_kernel>= 5.2 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.366.6.36
linuxlinux_kernel>= 6.7 < 6.9.76.9.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.