PT-2024-23794 · Linux+3 · Linux Kernel+3

Jan Beulich

·

Published

2024-07-16

·

Updated

2025-11-09

·

CVE-2024-31143

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns an optional feature of PCI MSI called "Multiple Message" that allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of these consecutive vectors needs to happen all in one go. In this handling, an error path could be taken in different situations, with or without a particular lock held. This error path wrongly releases the lock even when it is not currently held.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Locking

Weakness Enumeration

Related Identifiers

BDU:2025-09862
CVE-2024-31143
DSA-5836-1
MGASA-2025-0270
OPENSUSE-SU-2024:14204-1
OPENSUSE-SU-2024_2531-1
OPENSUSE-SU-2024_3423-1
SUSE-SU-2024:2531-1
SUSE-SU-2024:2533-1
SUSE-SU-2024:2534-1
SUSE-SU-2024:2535-1
SUSE-SU-2024:2654-1
SUSE-SU-2024:3423-1

Affected Products

Debian
Linux Kernel
Red Os
Suse