cbcvebase.
CVE-2024-53067
published 2024-11-19

CVE-2024-53067: In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Start the RTC update work later The RTC update work involves runtime…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.8th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Start the RTC update work later The RTC update work involves runtime resuming the UFS controller. Hence, only start the RTC update work after runtime power management in the UFS driver has been fully initialized. This patch fixes the following kernel crash: Internal error: Oops: 0000000096000006 [#1] PREEMPT SMP Workqueue: events ufshcd_rtc_work Call trace: _raw_spin_lock_irqsave+0x34/0x8c (P) pm_runtime_get_if_active+0x24/0x9c (L) pm_runtime_get_if_active+0x24/0x9c ufshcd_rtc_work+0x138/0x1b4 process_one_work+0x148/0x288 worker_thread+0x2cc/0x3d4 kthread+0x110/0x114 ret_from_fork+0x10/0x20

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.9-1 (forky)linux 6.11.9-1 (forky)
linuxlinux
linuxlinux>= 06701a545e9a3c4e007cff6872a074bf97c40619 < 6e34b9d7caa5a4c831b74bdfed5ef86fa0c033166e34b9d7caa5a4c831b74bdfed5ef86fa0c03316
linuxlinux>= 6bf999e0eb41850d5c857102535d5c53b2ede224 < 4c25f784fba81227e0437337f962d34380d1c2504c25f784fba81227e0437337f962d34380d1c250
linuxlinux>= 6bf999e0eb41850d5c857102535d5c53b2ede224 < 54c814c8b23bc7617be3d46abdb896937695dbfa54c814c8b23bc7617be3d46abdb896937695dbfa
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.8 < 6.11.86.11.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.