CVE-2024-26806

MEDIUM

Linux Kernel 6.7-6.7.8 - Deadlock via SPI Controller Runtime PM Hooks

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: spi: cadence-qspi: remove system-wide suspend helper calls from runtime PM hooks The ->runtime_suspend() and ->runtime_resume() callbacks are not expected to call spi_controller_suspend() and spi_controller_resume(). Remove calls to those in the cadence-qspi driver. Those helpers have two roles currently: - They stop/start the queue, including dealing with the kworker. - They toggle the SPI controller SPI_CONTROLLER_SUSPENDED flag. It requires acquiring ctlr->bus_lock_mutex. Step one is irrelevant because cadence-qspi is not queued. Step two however has two implications: - A deadlock occurs, because ->runtime_resume() is called in a context where the lock is already taken (in the ->exec_op() callback, where the usage count is incremented). - It would disallow all operations once the device is auto-suspended. Here is a brief call tree highlighting the mutex deadlock: spi_mem_exec_op() ... spi_mem_access_start() mutex_lock(&ctlr->bus_lock_mutex) cqspi_exec_mem_op() pm_runtime_resume_and_get() cqspi_resume() spi_controller_resume() mutex_lock(&ctlr->bus_lock_mutex) ... spi_mem_access_end() mutex_unlock(&ctlr->bus_lock_mutex) ...

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-667
Status published
Products (9)
linux/Kernel 6.7.0 - 6.7.9linux
Linux/Linux < 6.7
Linux/Linux 0578a6dbfe7514db7134501cf93acc21cf13e479 - 041562ebc4759c9932b59a06527f8753b86da365
Linux/Linux 0578a6dbfe7514db7134501cf93acc21cf13e479 - 959043afe53ae80633e810416cee6076da6e91c6
Linux/Linux 6.7
Linux/Linux 6.7.9 - 6.7.*
Linux/Linux 6.8
linux/linux_kernel 6.8 rc1 (6 CPE variants)
linux/linux_kernel 6.7 - 6.7.9
Published Apr 04, 2024
Tracked Since Feb 18, 2026