CVE-2024-53067

MEDIUM

Linux Kernel 6.8-6.11.7 - Denial of Service via UFS RTC Update Work Initialization

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Start the RTC update work later The RTC update work involves runtime resuming the UFS controller. Hence, only start the RTC update work after runtime power management in the UFS driver has been fully initialized. This patch fixes the following kernel crash: Internal error: Oops: 0000000096000006 [#1] PREEMPT SMP Workqueue: events ufshcd_rtc_work Call trace: _raw_spin_lock_irqsave+0x34/0x8c (P) pm_runtime_get_if_active+0x24/0x9c (L) pm_runtime_get_if_active+0x24/0x9c ufshcd_rtc_work+0x138/0x1b4 process_one_work+0x148/0x288 worker_thread+0x2cc/0x3d4 kthread+0x110/0x114 ret_from_fork+0x10/0x20

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (10)
linux/Kernel 6.8.0 - 6.11.8linux
Linux/Linux < 6.8
Linux/Linux 06701a545e9a3c4e007cff6872a074bf97c40619 - 6e34b9d7caa5a4c831b74bdfed5ef86fa0c03316
Linux/Linux 6.11.8 - 6.11.*
Linux/Linux 6.12
Linux/Linux 6.8
Linux/Linux 6bf999e0eb41850d5c857102535d5c53b2ede224 - 4c25f784fba81227e0437337f962d34380d1c250
Linux/Linux 6bf999e0eb41850d5c857102535d5c53b2ede224 - 54c814c8b23bc7617be3d46abdb896937695dbfa
linux/linux_kernel 6.12 rc1 (6 CPE variants)
linux/linux_kernel 6.8 - 6.11.8
Published Nov 19, 2024
Tracked Since Feb 18, 2026