CVE-2024-42127
In the Linux kernel, the following vulnerability has been resolved: drm/lima: fix shared irq handling on driver remove lima uses a shared interrupt, so the interrupt handlers must be prepared to be called at any time.
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/lima: fix shared irq handling on driver remove lima uses a shared interrupt, so the interrupt handlers must be prepared to be called at any time. At driver removal time, the clocks are disabled early and the interrupts stay registered until the very end of the remove process due to the devm usage. This is potentially a bug as the interrupts access device registers which assumes clocks are enabled. A crash can be triggered by removing the driver in a kernel with CONFIG_DEBUG_SHIRQ enabled. This patch frees the interrupts at each lima device finishing callback so that the handlers are already unregistered by the time we fully disable clocks.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/04d531b9a1875846d4f89953b469ad463aa7a770Patch
- https://git.kernel.org/stable/c/0a487e977cb8897ae4c51ecd34bbaa2b005266c9Patch
- https://git.kernel.org/stable/c/0d60c43df59ef01c08dc7b0c45495178f9d05a13Patch
- https://git.kernel.org/stable/c/17fe8b75aaf0bb1bdc31368963446b421c22d0afPatch
- https://git.kernel.org/stable/c/25d0d9b83d855cbc5d5aa5ae3cd79d55ea0c84a8Patch
- https://git.kernel.org/stable/c/a6683c690bbfd1f371510cb051e8fa49507f3f5ePatch
- https://git.kernel.org/stable/c/b5daf9217a50636a969bc1965f827878aeb09ffePatch
- https://git.kernel.org/stable/c/04d531b9a1875846d4f89953b469ad463aa7a770Patch
- https://git.kernel.org/stable/c/0a487e977cb8897ae4c51ecd34bbaa2b005266c9Patch
- https://git.kernel.org/stable/c/0d60c43df59ef01c08dc7b0c45495178f9d05a13Patch
- https://git.kernel.org/stable/c/17fe8b75aaf0bb1bdc31368963446b421c22d0afPatch
- https://git.kernel.org/stable/c/25d0d9b83d855cbc5d5aa5ae3cd79d55ea0c84a8Patch
- https://git.kernel.org/stable/c/a6683c690bbfd1f371510cb051e8fa49507f3f5ePatch
- https://git.kernel.org/stable/c/b5daf9217a50636a969bc1965f827878aeb09ffePatch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.