CVE-2024-53067
MEDIUMLinux Kernel 6.8-6.11.7 - Denial of Service via UFS RTC Update Work Initialization
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Start the RTC update work later The RTC update work involves runtime resuming the UFS controller. Hence, only start the RTC update work after runtime power management in the UFS driver has been fully initialized. This patch fixes the following kernel crash: Internal error: Oops: 0000000096000006 [#1] PREEMPT SMP Workqueue: events ufshcd_rtc_work Call trace: _raw_spin_lock_irqsave+0x34/0x8c (P) pm_runtime_get_if_active+0x24/0x9c (L) pm_runtime_get_if_active+0x24/0x9c ufshcd_rtc_work+0x138/0x1b4 process_one_work+0x148/0x288 worker_thread+0x2cc/0x3d4 kthread+0x110/0x114 ret_from_fork+0x10/0x20
References (3)
Core 3
Scores
CVSS v3
5.5
EPSS
0.0021
EPSS Percentile
11.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (10)
linux/Kernel
6.8.0 - 6.11.8linux
Linux/Linux
< 6.8
Linux/Linux
06701a545e9a3c4e007cff6872a074bf97c40619 - 6e34b9d7caa5a4c831b74bdfed5ef86fa0c03316
Linux/Linux
6.11.8 - 6.11.*
Linux/Linux
6.12
Linux/Linux
6.8
Linux/Linux
6bf999e0eb41850d5c857102535d5c53b2ede224 - 4c25f784fba81227e0437337f962d34380d1c250
Linux/Linux
6bf999e0eb41850d5c857102535d5c53b2ede224 - 54c814c8b23bc7617be3d46abdb896937695dbfa
linux/linux_kernel
6.12 rc1 (6 CPE variants)
linux/linux_kernel
6.8 - 6.11.8
Published
Nov 19, 2024
Tracked Since
Feb 18, 2026