PT-2024-9643 · Linux+10 · Linux Kernel+10

Published

2024-06-14

·

Updated

2025-09-29

·

CVE-2024-40904

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.10.0-rc2-syzkaller-g8867bbd4a056
Description The vulnerability is related to a CPU lockup caused by excessive log messages in the cdc-wdm driver. The interrupt-URB completion callback in the driver takes too long, and the driver's immediate resubmission of interrupt URBs with -EPROTO status combined with the dummy-hcd emulation causes a CPU lockup. The issue can be prevented by ratelimiting the two dev err() calls, which are replaced with dev err ratelimited().
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the cdc-wdm driver. Specifically, update to a version later than 6.10.0-rc2-syzkaller-g8867bbd4a056. As a temporary workaround, consider ratelimiting the dev err() calls in the cdc-wdm driver to prevent excessive log messages.

Exploit

Fix

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:7000
ALSA-2024:7001
ALSA-2024:8617
ALSA-2025_16880
ALT-PU-2024-12537
ALT-PU-2024-13979
ALT-PU-2024-14046
ALT-PU-2024-9967
BDU:2024-11355
CESA-2024_7000
CESA-2024_7001
CVE-2024-40904
DLA-4008-1
DSA-5730-1
DSA-5731-1
INFSA-2024_7000
INFSA-2024_7001
INFSA-2024_8617
OESA-2024-1894
OESA-2024-1895
OESA-2024-1896
OESA-2024-1898
OPENSUSE-SU-2024_2947-1
RHSA-2024:7000
RHSA-2024:7001
RHSA-2024:8617
RHSA-2024_7000
RHSA-2024_7001
RHSA-2024_8617
RLSA-2024:7001
RLSA-2024:8617
SUSE-SU-2024:2892-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2940-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-6999-1
USN-6999-2
USN-7003-1
USN-7003-2
USN-7003-3
USN-7003-4
USN-7003-5
USN-7004-1
USN-7005-1
USN-7005-2
USN-7006-1
USN-7007-1
USN-7007-2
USN-7007-3
USN-7008-1
USN-7009-1
USN-7009-2
USN-7019-1
USN-7029-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu