CVE-2024-27021

HIGH

Linux Kernel - Deadlock on Module Removal via LED Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: r8169: fix LED-related deadlock on module removal Binding devm_led_classdev_register() to the netdev is problematic because on module removal we get a RTNL-related deadlock. Fix this by avoiding the device-managed LED functions. Note: We can safely call led_classdev_unregister() for a LED even if registering it failed, because led_classdev_unregister() detects this and is a no-op in this case.

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 1.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-667
Status published
Products (12)
fedoraproject/fedora 38
fedoraproject/fedora 39
fedoraproject/fedora 40
linux/Kernel 6.8.0 - 6.8.8linux
Linux/Linux < 6.8
Linux/Linux 18764b883e157e28126b54e7d4ba9dd487d5bf54 - 19fa4f2a85d777a8052e869c1b892a2f7556569d
Linux/Linux 18764b883e157e28126b54e7d4ba9dd487d5bf54 - 53d986f39acd8ea11c9e460732bfa5add66360d9
Linux/Linux 6.8
Linux/Linux 6.8.8 - 6.8.*
Linux/Linux 6.9
... and 2 more
Published May 01, 2024
Tracked Since Feb 18, 2026