CVE-2024-27021
HIGHLinux Kernel - Deadlock on Module Removal via LED Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: r8169: fix LED-related deadlock on module removal Binding devm_led_classdev_register() to the netdev is problematic because on module removal we get a RTNL-related deadlock. Fix this by avoiding the device-managed LED functions. Note: We can safely call led_classdev_unregister() for a LED even if registering it failed, because led_classdev_unregister() detects this and is a no-op in this case.
References (5)
Core 5
Core References
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/DAMSOZXJEPUOXW33WZYWCVAY7Z5S7OOY/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/GCBZZEC7L7KTWWAS2NLJK6SO3IZIL4WW/
Scores
CVSS v3
7.8
EPSS
0.0001
EPSS Percentile
1.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-667
Status
published
Products (12)
fedoraproject/fedora
38
fedoraproject/fedora
39
fedoraproject/fedora
40
linux/Kernel
6.8.0 - 6.8.8linux
Linux/Linux
< 6.8
Linux/Linux
18764b883e157e28126b54e7d4ba9dd487d5bf54 - 19fa4f2a85d777a8052e869c1b892a2f7556569d
Linux/Linux
18764b883e157e28126b54e7d4ba9dd487d5bf54 - 53d986f39acd8ea11c9e460732bfa5add66360d9
Linux/Linux
6.8
Linux/Linux
6.8.8 - 6.8.*
Linux/Linux
6.9
... and 2 more
Published
May 01, 2024
Tracked Since
Feb 18, 2026