cbcvebase.
CVE-2024-47658
published 2024-10-09

CVE-2024-47658: In the Linux kernel, the following vulnerability has been resolved: crypto: stm32/cryp - call finalize with bh disabled The finalize operation in interrupt…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.47%
38.1th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: stm32/cryp - call finalize with bh disabled The finalize operation in interrupt mode produce a produces a spinlock recursion warning. The reason is the fact that BH must be disabled during this process.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.10.9-1 (forky)linux 6.10.9-1 (forky)
linuxlinux
linuxlinux>= 9e054ec21ef8344345b28603fb272fe999f735db < d93a2f86b0a998aa1f0870c85a2a60a0771ef89ad93a2f86b0a998aa1f0870c85a2a60a0771ef89a
linuxlinux>= 9e054ec21ef8344345b28603fb272fe999f735db < 5d734665cd5d93270731e0ff1dd673fec677f4475d734665cd5d93270731e0ff1dd673fec677f447
linuxlinux>= 9e054ec21ef8344345b28603fb272fe999f735db < 56ddb9aa3b324c2d9645b5a7343e46010cf3f6ce56ddb9aa3b324c2d9645b5a7343e46010cf3f6ce
linuxlinux_kernel< 6.6.506.6.50
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.7 < 6.10.96.10.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.