cbcvebase.
CVE-2024-42140
published 2024-07-30

CVE-2024-42140: In the Linux kernel, the following vulnerability has been resolved: riscv: kexec: Avoid deadlock in kexec crash path If the kexec crash code is called in the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.9th percentile
In the Linux kernel, the following vulnerability has been resolved: riscv: kexec: Avoid deadlock in kexec crash path If the kexec crash code is called in the interrupt context, the machine_kexec_mask_interrupts() function will trigger a deadlock while trying to acquire the irqdesc spinlock and then deactivate irqchip in irq_set_irqchip_state() function. Unlike arm64, riscv only requires irq_eoi handler to complete EOI and keeping irq_set_irqchip_state() will only leave this possible deadlock without any use. So we simply remove it.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 12f237200c169a8667cf9dca7a40df8d7917b9fd < bb80a7911218bbab2a69b5db7d2545643ab0073dbb80a7911218bbab2a69b5db7d2545643ab0073d
linuxlinux>= 5.15.82 < 5.15.1635.15.163
linuxlinux>= 6.0.12 < 6.16.1
linuxlinux>= b17d19a5314a37f7197afd1a0200affd21a7227d < 653deee48a4682ea17a05b96fb6842795ab5943c653deee48a4682ea17a05b96fb6842795ab5943c
linuxlinux>= b17d19a5314a37f7197afd1a0200affd21a7227d < 7692c9b6baacdee378435f58f19baf0eb69e41557692c9b6baacdee378435f58f19baf0eb69e4155
linuxlinux>= b17d19a5314a37f7197afd1a0200affd21a7227d < 484dd545271d02d1571e1c6b62ea7df9dbe5e692484dd545271d02d1571e1c6b62ea7df9dbe5e692
linuxlinux>= b17d19a5314a37f7197afd1a0200affd21a7227d < c562ba719df570c986caf0941fea2449150bcbc4c562ba719df570c986caf0941fea2449150bcbc4
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.15.82 < 5.15.1635.15.163
linuxlinux_kernel>= 6.0.12 < 6.1.986.1.98
linuxlinux_kernel>= 6.2 < 6.6.396.6.39
linuxlinux_kernel>= 6.7 < 6.9.96.9.9
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.