PT-2024-6942 · Linux+8 · Linux Kernel+8
Ian Ray
·
Published
2024-06-21
·
Updated
2026-05-26
·
CVE-2024-42253
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to a race condition in the Linux kernel's gpio: pca953x module. Specifically, the problem occurs when a request races against irq bus sync unlock() approximately once per thousand reboots on an i.MX8MP based system. To avoid races, it is essential to ensure that the
i2c lock is held when setting interrupt latch and mask in pca953x irq bus sync unlock(). The other non-probe call site, pca953x gpio set multiple(), ensures the lock is held before calling pca953x write regs().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Improper Locking
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu