cbcvebase.
CVE-2024-58090
published 2025-03-27

CVE-2024-58090: In the Linux kernel, the following vulnerability has been resolved: sched/core: Prevent rescheduling when interrupts are disabled David reported a warning…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.8th percentile
In the Linux kernel, the following vulnerability has been resolved: sched/core: Prevent rescheduling when interrupts are disabled David reported a warning observed while loop testing kexec jump: Interrupts enabled after irqrouter_resume+0x0/0x50 WARNING: CPU: 0 PID: 560 at drivers/base/syscore.c:103 syscore_resume+0x18a/0x220 kernel_kexec+0xf6/0x180 __do_sys_reboot+0x206/0x250 do_syscall_64+0x95/0x180 The corresponding interrupt flag trace: hardirqs last enabled at (15573): [] __up_console_sem+0x7e/0x90 hardirqs last disabled at (15580): [] __up_console_sem+0x63/0x90 That means __up_console_sem() was invoked with interrupts enabled. Further instrumentation revealed that in the interrupt disabled section of kexec jump one of the syscore_suspend() callbacks woke up a task, which set the NEED_RESCHED flag. A later callback in the resume path invoked cond_resched() which in turn led to the invocation of the scheduler: __cond_resched+0x21/0x60 down_timeout+0x18/0x60 acpi_os_wait_semaphore+0x4c/0x80 acpi_ut_acquire_mutex+0x3d/0x100 acpi_ns_get_node+0x27/0x60 acpi_ns_evaluate+0x1cb/0x2d0 acpi_rs_set_srs_method_data+0x156/0x190 acpi_pci_link_set+0x11c/0x290 irqrouter_resume+0x54/0x60 syscore_resume+0x6a/0x200 kernel_kexec+0x145/0x1c0 __do_sys_reboot+0xeb/0x240 do_syscall_64+0x95/0x180 This is a long standing problem, which probably got more visible with the recent printk changes. Something does a task wakeup and the scheduler sets the NEED_RESCHED flag. cond_resched() sees it set and invokes schedule() from a completely bogus context. The scheduler enables interrupts after context switching, which causes the above warning at the end. Quite some of the code paths in syscore_suspend()/resume() can result in triggering a wakeup with the exactly same consequences. They might not have done so yet, but as they share a lot of code with normal operations it's just a question of time. The problem only affects the PREEMPT_NONE and PREEMPT_VOLUNTARY scheduling models. Full p

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 321794b75ac968f0bb6b9c913581949452a8d992321794b75ac968f0bb6b9c913581949452a8d992
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1651f5731b378616565534eb9cda30e258cebebc1651f5731b378616565534eb9cda30e258cebebc
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 288fdb8dcb71ec77b76ab8b8a06bc10f595ea504288fdb8dcb71ec77b76ab8b8a06bc10f595ea504
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 84586322e010164eedddfcd0a0894206ae7d931784586322e010164eedddfcd0a0894206ae7d9317
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 68786ab0935ccd5721283b7eb7f4d2f2942c7a5268786ab0935ccd5721283b7eb7f4d2f2942c7a52
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0362847c520747b44b574d363705d8af0621727a0362847c520747b44b574d363705d8af0621727a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b927c8539f692fb1f9c2f42e6c8ea2d94956f921b927c8539f692fb1f9c2f42e6c8ea2d94956f921
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 82c387ef7568c0d96a918a5a78d9cad6256cfa1582c387ef7568c0d96a918a5a78d9cad6256cfa15
linuxlinux_kernel< 5.4.2915.4.291
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1306.1.130
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.66.13.6
linuxlinux_kernel>= 6.2 < 6.6.816.6.81

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.