cbcvebase.
CVE-2024-57939
published 2025-01-21

CVE-2024-57939: In the Linux kernel, the following vulnerability has been resolved: riscv: Fix sleeping in invalid context in die() die() can be called in exception handler…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.4th percentile
In the Linux kernel, the following vulnerability has been resolved: riscv: Fix sleeping in invalid context in die() die() can be called in exception handler, and therefore cannot sleep. However, die() takes spinlock_t which can sleep with PREEMPT_RT enabled. That causes the following warning: BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48 in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 285, name: mutex preempt_count: 110001, expected: 0 RCU nest depth: 0, expected: 0 CPU: 0 UID: 0 PID: 285 Comm: mutex Not tainted 6.12.0-rc7-00022-ge19049cf7d56-dirty #234 Hardware name: riscv-virtio,qemu (DT) Call Trace: dump_backtrace+0x1c/0x24 show_stack+0x2c/0x38 dump_stack_lvl+0x5a/0x72 dump_stack+0x14/0x1c __might_resched+0x130/0x13a rt_spin_lock+0x2a/0x5c die+0x24/0x112 do_trap_insn_illegal+0xa0/0xea _new_vmalloc_restore_context_a0+0xcc/0xd8 Oops - illegal instruction [#1] Switch to use raw_spinlock_t, which does not sleep even with PREEMPT_RT enabled.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= 76d2a0493a17d4c8ecc781366850c3c4f8e1a446 < 8c38baa03ac8e18140faf36a3b955d30cad48e748c38baa03ac8e18140faf36a3b955d30cad48e74
linuxlinux>= 76d2a0493a17d4c8ecc781366850c3c4f8e1a446 < 10c24df2e303f517fab0359392c11b6b1d553f2b10c24df2e303f517fab0359392c11b6b1d553f2b
linuxlinux>= 76d2a0493a17d4c8ecc781366850c3c4f8e1a446 < c21df31fc2a4afc02a6e56511364e9e793ea92ecc21df31fc2a4afc02a6e56511364e9e793ea92ec
linuxlinux>= 76d2a0493a17d4c8ecc781366850c3c4f8e1a446 < f48f060a4b36b5e96628f6c3fb1540f1e8dedb69f48f060a4b36b5e96628f6c3fb1540f1e8dedb69
linuxlinux>= 76d2a0493a17d4c8ecc781366850c3c4f8e1a446 < 76ab0afcdbe8c9685b589016ee1c0e25fe59670776ab0afcdbe8c9685b589016ee1c0e25fe596707
linuxlinux>= 76d2a0493a17d4c8ecc781366850c3c4f8e1a446 < 6a97f4118ac07cfdc316433f385dbdc12af5025e6a97f4118ac07cfdc316433f385dbdc12af5025e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 4.15 < 5.10.2345.10.234
linuxlinux_kernel5.11 – 5.15.177
linuxlinux_kernel5.16 – 6.1.125
linuxlinux_kernel6.2 – 6.6.72
linuxlinux_kernel6.7 – 6.12.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.