cbcvebase.
CVE-2024-42090
published 2024-07-29

CVE-2024-42090: In the Linux kernel, the following vulnerability has been resolved: pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER In create_pinctrl()…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.6th percentile
In the Linux kernel, the following vulnerability has been resolved: pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER In create_pinctrl(), pinctrl_maps_mutex is acquired before calling add_setting(). If add_setting() returns -EPROBE_DEFER, create_pinctrl() calls pinctrl_free(). However, pinctrl_free() attempts to acquire pinctrl_maps_mutex, which is already held by create_pinctrl(), leading to a potential deadlock. This patch resolves the issue by releasing pinctrl_maps_mutex before calling pinctrl_free(), preventing the deadlock. This bug was discovered and resolved using Coverity Static Analysis Security Testing (SAST) by Synopsys, Inc.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= 42fed7ba44e4e8c1fb27b28ad14490cb1daff3c7 < e65a0dc2e85efb28e182aca50218e8a056d0ce04e65a0dc2e85efb28e182aca50218e8a056d0ce04
linuxlinux>= 42fed7ba44e4e8c1fb27b28ad14490cb1daff3c7 < 420ce1261907e5dbeda1e4daffd5b6c76f8188c0420ce1261907e5dbeda1e4daffd5b6c76f8188c0
linuxlinux>= 42fed7ba44e4e8c1fb27b28ad14490cb1daff3c7 < b813e3fd102a959c5b208ed68afe27e0137a561bb813e3fd102a959c5b208ed68afe27e0137a561b
linuxlinux>= 42fed7ba44e4e8c1fb27b28ad14490cb1daff3c7 < 01fe2f885f7813f8aed5d3704b384a97b1116a9e01fe2f885f7813f8aed5d3704b384a97b1116a9e
linuxlinux>= 42fed7ba44e4e8c1fb27b28ad14490cb1daff3c7 < b36efd2e3e22a329444b6b24fa48df6d20ae66e6b36efd2e3e22a329444b6b24fa48df6d20ae66e6
linuxlinux>= 42fed7ba44e4e8c1fb27b28ad14490cb1daff3c7 < 4038c57bf61631219b31f1bd6e92106ec7f084dc4038c57bf61631219b31f1bd6e92106ec7f084dc
linuxlinux>= 42fed7ba44e4e8c1fb27b28ad14490cb1daff3c7 < 48a7a7c9571c3e62f17012dd7f2063e926179ddd48a7a7c9571c3e62f17012dd7f2063e926179ddd
linuxlinux>= 42fed7ba44e4e8c1fb27b28ad14490cb1daff3c7 < adec57ff8e66aee632f3dd1f93787c13d112b7a1adec57ff8e66aee632f3dd1f93787c13d112b7a1
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 6.9.8-16.9.8-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 0 < 4.4.0-262.2964.4.0-262.296
linuxlinux_kernel>= 0 < 4.15.0-232.2444.15.0-232.244
linuxlinux_kernel>= 3.10 < 4.19.3174.19.317
linuxlinux_kernel>= 4.20 < 5.4.2795.4.279
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.976.1.97
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.