CVE-2024-35953

MEDIUM

Linux Kernel 6.3-6.6.27 - Denial of Service via Deadlock in Context XA

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix deadlock in context_xa ivpu_device->context_xa is locked both in kernel thread and IRQ context. It requires XA_FLAGS_LOCK_IRQ flag to be passed during initialization otherwise the lock could be acquired from a thread and interrupted by an IRQ that locks it for the second time causing the deadlock. This deadlock was reported by lockdep and observed in internal tests.

Scores

CVSS v3 5.5
EPSS 0.0017
EPSS Percentile 6.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-667
Status published
Products (12)
linux/Kernel 6.3.0 - 6.6.28linux
linux/Kernel 6.7.0 - 6.8.7linux
Linux/Linux < 6.3
Linux/Linux 35b137630f08d913fc2e33df33ccc2570dff3f7d - d43e11d9c7fcb16f18bd46ab2556c2772ffc5775
Linux/Linux 35b137630f08d913fc2e33df33ccc2570dff3f7d - e6011411147209bc0cc14628cbc155356837e52a
Linux/Linux 35b137630f08d913fc2e33df33ccc2570dff3f7d - fd7726e75968b27fe98534ccbf47ccd6fef686f3
Linux/Linux 6.3
Linux/Linux 6.6.28 - 6.6.*
Linux/Linux 6.8.7 - 6.8.*
Linux/Linux 6.9
... and 2 more
Published May 20, 2024
Tracked Since Feb 18, 2026