CVE-2024-27003

MEDIUM

Linux Kernel - Deadlock via clk_summary Debugfs

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: clk: Get runtime PM before walking tree for clk_summary Similar to the previous commit, we should make sure that all devices are runtime resumed before printing the clk_summary through debugfs. Failure to do so would result in a deadlock if the thread is resuming a device to print clk state and that device is also runtime resuming in another thread, e.g the screen is turning on and the display driver is starting up. We remove the calls to clk_pm_runtime_{get,put}() in this path because they're superfluous now that we know the devices are runtime resumed. This also squashes a bug where the return value of clk_pm_runtime_get() wasn't checked, leading to an RPM count underflow on error paths.

Scores

CVSS v3 5.5
EPSS 0.0017
EPSS Percentile 6.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-667
Status published
Products (15)
linux/Kernel 5.17.0 - 6.1.88linux
linux/Kernel 6.2.0 - 6.6.29linux
linux/Kernel 6.7.0 - 6.8.8linux
Linux/Linux < 5.17
Linux/Linux 1bb294a7981c737e2311a78e4086635ac0220ace - 2c077fdfd09dffb31a890e5095c8ab205138a42e
Linux/Linux 1bb294a7981c737e2311a78e4086635ac0220ace - 83ada89e4a86e2b28ea2b5113c76d6dc7560a4d0
Linux/Linux 1bb294a7981c737e2311a78e4086635ac0220ace - 9d1e795f754db1ac3344528b7af0b17b8146f321
Linux/Linux 1bb294a7981c737e2311a78e4086635ac0220ace - b457105309d388e4081c716cf7b81d517ff74db4
Linux/Linux 5.17
Linux/Linux 6.1.88 - 6.1.*
... and 5 more
Published May 01, 2024
Tracked Since Feb 18, 2026