PT-2025-3021 · Linux+3 · Linux Kernel+3

Published

2024-12-12

·

Updated

2025-09-29

·

CVE-2024-54191

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.12.0-rc6+
Description A circular locking dependency warning has been detected in the Linux kernel's Bluetooth module. This issue occurs when the iso sock recvmsg function is called, which can lead to a deadlock scenario. The warning is triggered by the kernel's locking mechanism, which detects a possible circular locking dependency between the hdev->lock and sk lock-AF BLUETOOTH locks. The existing dependency chain is complex and involves multiple locks, including sk lock-AF BLUETOOTH-BTPROTO ISO and sk lock-AF BLUETOOTH. The issue is resolved by reworking the iso sock recvmsg function to ensure that the socket lock is always released before calling a function that locks hdev.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the circular locking dependency warning. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-17881
BDU:2025-15352
CVE-2024-54191
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Ubuntu