cbcvebase.
CVE-2024-42290
published 2024-08-17

CVE-2024-42290: In the Linux kernel, the following vulnerability has been resolved: irqchip/imx-irqsteer: Handle runtime power management correctly The power domain is…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.0th percentile
In the Linux kernel, the following vulnerability has been resolved: irqchip/imx-irqsteer: Handle runtime power management correctly The power domain is automatically activated from clk_prepare(). However, on certain platforms like i.MX8QM and i.MX8QXP, the power-on handling invokes sleeping functions, which triggers the 'scheduling while atomic' bug in the context switch path during device probing: BUG: scheduling while atomic: kworker/u13:1/48/0x00000002 Call trace: __schedule_bug+0x54/0x6c __schedule+0x7f0/0xa94 schedule+0x5c/0xc4 schedule_preempt_disabled+0x24/0x40 __mutex_lock.constprop.0+0x2c0/0x540 __mutex_lock_slowpath+0x14/0x20 mutex_lock+0x48/0x54 clk_prepare_lock+0x44/0xa0 clk_prepare+0x20/0x44 imx_irqsteer_resume+0x28/0xe0 pm_generic_runtime_resume+0x2c/0x44 __genpd_runtime_resume+0x30/0x80 genpd_runtime_resume+0xc8/0x2c0 __rpm_callback+0x48/0x1d8 rpm_callback+0x6c/0x78 rpm_resume+0x490/0x6b4 __pm_runtime_resume+0x50/0x94 irq_chip_pm_get+0x2c/0xa0 __irq_do_set_handler+0x178/0x24c irq_set_chained_handler_and_data+0x60/0xa4 mxc_gpio_probe+0x160/0x4b0 Cure this by implementing the irq_bus_lock/sync_unlock() interrupt chip callbacks and handle power management in them as they are invoked from non-atomic context. [ tglx: Rewrote change log, added Fixes tag ]

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 0136afa08967f6e160b9b4e85a7a70e4180a8333 < a590e8dea3df2639921f874d763be961dd74e8f9a590e8dea3df2639921f874d763be961dd74e8f9
linuxlinux>= 0136afa08967f6e160b9b4e85a7a70e4180a8333 < 3a2884a44e5cda192df1b28e9925661f79f599a13a2884a44e5cda192df1b28e9925661f79f599a1
linuxlinux>= 0136afa08967f6e160b9b4e85a7a70e4180a8333 < fa1803401e1c360efe6342fb41d161cc51748a11fa1803401e1c360efe6342fb41d161cc51748a11
linuxlinux>= 0136afa08967f6e160b9b4e85a7a70e4180a8333 < 58c56735facb225a5c46fa4b8bbbe7f31d1cb89458c56735facb225a5c46fa4b8bbbe7f31d1cb894
linuxlinux>= 0136afa08967f6e160b9b4e85a7a70e4180a8333 < 21bd3f9e7f924cd2fc892a484e7a50c7e184756521bd3f9e7f924cd2fc892a484e7a50c7e1847565
linuxlinux>= 0136afa08967f6e160b9b4e85a7a70e4180a8333 < f8ae38f1dfe652779c7c613facbc257cec00ac44f8ae38f1dfe652779c7c613facbc257cec00ac44
linuxlinux>= 0136afa08967f6e160b9b4e85a7a70e4180a8333 < 33b1c47d1fc0b5f06a393bb915db85baacba18ea33b1c47d1fc0b5f06a393bb915db85baacba18ea
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.0 < 5.4.2825.4.282
linuxlinux_kernel>= 5.11 < 5.15.1655.15.165
linuxlinux_kernel>= 5.16 < 6.1.1036.1.103
linuxlinux_kernel>= 5.5 < 5.10.2245.10.224
linuxlinux_kernel>= 6.2 < 6.6.446.6.44
linuxlinux_kernel>= 6.7 < 6.10.36.10.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.