cbcvebase.
CVE-2024-42127
published 2024-07-30

CVE-2024-42127: In the Linux kernel, the following vulnerability has been resolved: drm/lima: fix shared irq handling on driver remove lima uses a shared interrupt, so the…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/lima: fix shared irq handling on driver remove lima uses a shared interrupt, so the interrupt handlers must be prepared to be called at any time. At driver removal time, the clocks are disabled early and the interrupts stay registered until the very end of the remove process due to the devm usage. This is potentially a bug as the interrupts access device registers which assumes clocks are enabled. A crash can be triggered by removing the driver in a kernel with CONFIG_DEBUG_SHIRQ enabled. This patch frees the interrupts at each lima device finishing callback so that the handlers are already unregistered by the time we fully disable clocks.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < 0d60c43df59ef01c08dc7b0c45495178f9d05a130d60c43df59ef01c08dc7b0c45495178f9d05a13
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < 25d0d9b83d855cbc5d5aa5ae3cd79d55ea0c84a825d0d9b83d855cbc5d5aa5ae3cd79d55ea0c84a8
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < 17fe8b75aaf0bb1bdc31368963446b421c22d0af17fe8b75aaf0bb1bdc31368963446b421c22d0af
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < 0a487e977cb8897ae4c51ecd34bbaa2b005266c90a487e977cb8897ae4c51ecd34bbaa2b005266c9
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < 04d531b9a1875846d4f89953b469ad463aa7a77004d531b9a1875846d4f89953b469ad463aa7a770
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < b5daf9217a50636a969bc1965f827878aeb09ffeb5daf9217a50636a969bc1965f827878aeb09ffe
linuxlinux>= a1d2a6339961efc078208dc3b2f006e9e9a8e119 < a6683c690bbfd1f371510cb051e8fa49507f3f5ea6683c690bbfd1f371510cb051e8fa49507f3f5e
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.4.0-195.2155.4.0-195.215
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.11 < 5.15.1635.15.163
linuxlinux_kernel>= 5.16 < 6.1.986.1.98
linuxlinux_kernel>= 5.2 < 5.4.2805.4.280
linuxlinux_kernel>= 5.5 < 5.10.2225.10.222
linuxlinux_kernel>= 6.2 < 6.6.396.6.39
linuxlinux_kernel>= 6.7 < 6.9.96.9.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.