PT-2024-9809 · Linux +5 · Linux Kernel +5

Ronald Wahl

·

Published

2024-05-03

·

Updated

2024-11-29

·

CVE-2024-36962

CVSS v3.1
6.2
VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Name of the Vulnerable Software and Affected Versions:

Linux kernel (affected versions not specified)

Description:

The issue is related to the ks8851 component in the Linux kernel, which is associated with incorrect resource locking. This can lead to a denial of service. The problem arises when the `net rx action()` function triggers the `.start xmit` callback, protected by the same lock as the IRQ handler, potentially causing a hang due to attempting to claim an already claimed lock. The solution involves removing the BH manipulation and queuing received packets in the IRQ handler before pushing them into `netif rx()` outside the lock-protected critical section.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Weakness Enumeration

Related Identifiers

BDU:2024-11583
CVE-2024-36962
MGASA-2024-0263
MGASA-2024-0266
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3483-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu