cbcvebase.
CVE-2024-42085
published 2024-07-29

CVE-2024-42085: In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: remove lock of otg mode during gadget suspend/resume to avoid deadlock…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: remove lock of otg mode during gadget suspend/resume to avoid deadlock When config CONFIG_USB_DWC3_DUAL_ROLE is selected, and trigger system to enter suspend status with below command: echo mem > /sys/power/state There will be a deadlock issue occurring. Detailed invoking path as below: dwc3_suspend_common() spin_lock_irqsave(&dwc->lock, flags); lock, flags); gadget_driver is NULL or not. It causes the following code is executed and deadlock occurs when trying to get the spinlock. In fact, the root cause is the commit 5265397f9442("usb: dwc3: Remove DWC3 locking during gadget suspend/resume") that forgot to remove the lock of otg mode. So, remove the redundant lock of otg mode during gadget suspend/resume.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= 2fa487a9466760a4fb6f147aed6219379dabfc2e < 7026576e89094aa9a0062aa6d10cba18aa99944c7026576e89094aa9a0062aa6d10cba18aa99944c
linuxlinux>= 5.15.128 < 5.15.1625.15.162
linuxlinux>= 5265397f94424eaea596026fd34dc7acf474dcec < d77e2b5104c51d3668b9717c825a4a06998efe63d77e2b5104c51d3668b9717c825a4a06998efe63
linuxlinux>= 5265397f94424eaea596026fd34dc7acf474dcec < 17e2956633ca560b95f1cbbb297cfc2adf65064917e2956633ca560b95f1cbbb297cfc2adf650649
linuxlinux>= 5265397f94424eaea596026fd34dc7acf474dcec < f1274cfab183e69a7c7bafffcb4f50703c876276f1274cfab183e69a7c7bafffcb4f50703c876276
linuxlinux>= 5265397f94424eaea596026fd34dc7acf474dcec < 7838de15bb700c2898a7d741db9b1f3cbc86c1367838de15bb700c2898a7d741db9b1f3cbc86c136
linuxlinux>= f2bfd0a2a640ca2f308b6893a89cfb2ec31e8fde < 8731a0b180f6b5d52397c7aeea6eda9511a467a78731a0b180f6b5d52397c7aeea6eda9511a467a7
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.15.128 < 5.15.1625.15.162
linuxlinux_kernel>= 6.1 < 6.1.976.1.97
linuxlinux_kernel>= 6.2 < 6.6.376.6.37
linuxlinux_kernel>= 6.7 < 6.9.86.9.8
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.