cbcvebase.
CVE-2024-57949
published 2025-02-09

CVE-2024-57949: In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Don't enable interrupts in its_irq_set_vcpu_affinity() The following…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Don't enable interrupts in its_irq_set_vcpu_affinity() The following call-chain leads to enabling interrupts in a nested interrupt disabled section: irq_set_vcpu_affinity() irq_get_desc_lock() raw_spin_lock_irqsave() <--- Disable interrupts its_irq_set_vcpu_affinity() guard(raw_spinlock_irq) <--- Enables interrupts when leaving the guard() irq_put_desc_unlock() <--- Warns because interrupts are enabled This was broken in commit b97e8a2f7130, which replaced the original raw_spin_[un]lock() pair with guard(raw_spinlock_irq). Fix the issue by using guard(raw_spinlock). [ tglx: Massaged change log ]

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 2458f2362f695584bd824c922caa07ffc4fe0d5c < d7b0e89610dd45ac6cf0d6f99bfa9ccc787db344d7b0e89610dd45ac6cf0d6f99bfa9ccc787db344
linuxlinux>= 5c0fb9cb404a2efbbc319ff9d1b877cf4e47e950 < 6c84ff2e788fce0099ee3e71a3ed258b1ca1a2236c84ff2e788fce0099ee3e71a3ed258b1ca1a223
linuxlinux>= 6.1.95 < 6.1.1276.1.127
linuxlinux>= 6.6.35 < 6.6.746.6.74
linuxlinux>= 6.9.6 < 6.106.10
linuxlinux>= b97e8a2f7130a4b30d1502003095833d16c028b3 < 93955a7788121ab5a0f7f27e988b2ed1135a486693955a7788121ab5a0f7f27e988b2ed1135a4866
linuxlinux>= b97e8a2f7130a4b30d1502003095833d16c028b3 < 35cb2c6ce7da545f3b5cb1e6473ad7c3a6f0831035cb2c6ce7da545f3b5cb1e6473ad7c3a6f08310
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.11-16.12.11-1
linuxlinux_kernel>= 0 < 6.12.11-16.12.11-1
linuxlinux_kernel>= 0 < 6.8.0-62.656.8.0-62.65
linuxlinux_kernel>= 6.1.95 < 6.1.1276.1.127
linuxlinux_kernel>= 6.6.35 < 6.6.746.6.74
linuxlinux_kernel>= 6.9.6 < 6.12.116.12.11
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.