cbcvebase.
CVE-2024-46829
published 2024-09-27

CVE-2024-46829: In the Linux kernel, the following vulnerability has been resolved: rtmutex: Drop rt_mutex::wait_lock before scheduling rt_mutex_handle_deadlock() is called…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: rtmutex: Drop rt_mutex::wait_lock before scheduling rt_mutex_handle_deadlock() is called with rt_mutex::wait_lock held. In the good case it returns with the lock held and in the deadlock case it emits a warning and goes into an endless scheduling loop with the lock held, which triggers the 'scheduling in atomic' warning. Unlock rt_mutex::wait_lock in the dead lock case before issuing the warning and dropping into the schedule for ever loop. [ tglx: Moved unlock before the WARN(), removed the pointless comment, massaged changelog, added Fixes tag ]

Affected

52 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.10.49 < 3.113.11
linuxlinux>= 3.12.25 < 3.133.13
linuxlinux>= 3.14.10 < 3.153.15
linuxlinux>= 3.15.3 < 3.163.16
linuxlinux>= 3.2.61 < 3.33.3
linuxlinux>= 3.4.99 < 3.53.5
linuxlinux>= 3d5c9340d1949733eb37616abd15db36aef9a57c < 432efdbe7da5ecfcbc0c2180cfdbab1441752a38432efdbe7da5ecfcbc0c2180cfdbab1441752a38
linuxlinux>= 3d5c9340d1949733eb37616abd15db36aef9a57c < 6a976e9a47e8e5b326de671811561cab12e6fb1f6a976e9a47e8e5b326de671811561cab12e6fb1f
linuxlinux>= 3d5c9340d1949733eb37616abd15db36aef9a57c < 1401da1486dc1cdbef6025fd74a3977df3a3e5d01401da1486dc1cdbef6025fd74a3977df3a3e5d0
linuxlinux>= 3d5c9340d1949733eb37616abd15db36aef9a57c < 93f44655472d9cd418293d328f9d141ca234ad8393f44655472d9cd418293d328f9d141ca234ad83
linuxlinux>= 3d5c9340d1949733eb37616abd15db36aef9a57c < a92d81c9efec9280681c27a2c0a963fd0f1338e0a92d81c9efec9280681c27a2c0a963fd0f1338e0
linuxlinux>= 3d5c9340d1949733eb37616abd15db36aef9a57c < 85f03ca98e07cd0786738b56ae73740bce0ac27f85f03ca98e07cd0786738b56ae73740bce0ac27f
linuxlinux>= 3d5c9340d1949733eb37616abd15db36aef9a57c < f13b5afc5c4889569d84c3011ce449f61fccfb28f13b5afc5c4889569d84c3011ce449f61fccfb28
linuxlinux>= 3d5c9340d1949733eb37616abd15db36aef9a57c < d33d26036a0274b472299d7dcdaa5fb34329f91bd33d26036a0274b472299d7dcdaa5fb34329f91b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.