PT-2025-3061 · Linux+5 · Linux Kernel+5

Pablo Neira Ayuso

+2

·

Published

2024-12-06

·

Updated

2026-05-26

·

CVE-2024-54683

CVSS v4.0

5.7

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.74
Description A possible ABBA deadlock vulnerability has been identified in the Linux kernel, specifically in the netfilter IDLETIMER module. This issue occurs when the deletion of the last rule referencing a given idletimer happens simultaneously with a read of its file in sysfs, resulting in a possible circular locking dependency. A simple reproducer for this issue is provided, demonstrating how the deadlock can occur. The vulnerability is resolved by freeing the list mutex immediately after deleting the element from the list and then continuing with the teardown.
Recommendations For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later to resolve the vulnerability. As a temporary workaround, consider avoiding the simultaneous deletion and reading of idletimer rules to minimize the risk of deadlock.

Exploit

Fix

Improper Locking

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17881
ALT-PU-2025-12647
ALT-PU-2025-3496
AZL-55751
AZL-55771
BDU:2025-04667
CVE-2024-54683
ECHO-F535-3BCA-F093
MGASA-2025-0030
MGASA-2025-0032
OESA-2025-1159
OESA-2025-1160
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
SUSE-SU-2025:01600-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_01600-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7513-1
USN-7513-2
USN-7513-3
USN-7513-4
USN-7513-5
USN-7514-1
USN-7515-1
USN-7515-2
USN-7522-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu