CVE-2024-41080

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/07/2024
Last modified:
17/11/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> io_uring: fix possible deadlock in io_register_iowq_max_workers()<br /> <br /> The io_register_iowq_max_workers() function calls io_put_sq_data(),<br /> which acquires the sqd-&gt;lock without releasing the uring_lock.<br /> Similar to the commit 009ad9f0c6ee ("io_uring: drop ctx-&gt;uring_lock<br /> before acquiring sqd-&gt;lock"), this can lead to a potential deadlock<br /> situation.<br /> <br /> To resolve this issue, the uring_lock is released before calling<br /> io_put_sq_data(), and then it is re-acquired after the function call.<br /> <br /> This change ensures that the locks are acquired in the correct<br /> order, preventing the possibility of a deadlock.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.9.11 (excluding)