Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Binbin Zhou

#46261of 53,639
5.5Total CVSS
Vulnerabilities · 1
PT-2024-33944
5.5
2024-10-09
Linux · Linux Kernel · CVE-2024-50111
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.61 Description: The issue is related to the Linux kernel, specifically the LoongArch architecture, where an unaligned access exception can be triggered in an irq-enabled context, such as user mode. This can cause the `do ale()` function to call `get user()`, which may lead to a sleep, resulting in a BUG message indicating a sleeping function called from an invalid context. The estimated number of potentially affected devices is not provided. There is no information about real-world incidents where this issue was exploited. Recommendations: To resolve the issue, update to Linux kernel version 6.6.61 or later. As a temporary workaround, consider disabling the `do ale()` function until a patch is available. However, this may have unintended consequences and should be approached with caution. At the moment, there is no other information about additional mitigation measures.