PT-2024-34095 · Lenovo+3 · Lenovo Thinkpad X13S+3

Published

2024-10-09

·

Updated

2025-02-28

·

CVE-2024-50266

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A recent change in the venus driver results in a stuck clock on certain devices, such as the Lenovo ThinkPad X13s, when streaming video in firefox. This issue is related to the use of HW CTRL TRIGGER for vcodec GDSCs. The problem occurs when using the out-of-tree sm8350/sc8280xp venus support.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14144
CVE-2024-50266
USN-7276-1
USN-7277-1
USN-7310-1

Affected Products

Lenovo Thinkpad X13S
Linuxmint
Ubuntu
Firefox