CVE-2024-50266
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/11/2024
Last modified:
01/10/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
clk: qcom: videocc-sm8350: use HW_CTRL_TRIGGER for vcodec GDSCs<br />
<br />
A recent change in the venus driver results in a stuck clock on the<br />
Lenovo ThinkPad X13s, for example, when streaming video in firefox:<br />
<br />
video_cc_mvs0_clk status stuck at &#39;off&#39;<br />
WARNING: CPU: 6 PID: 2885 at drivers/clk/qcom/clk-branch.c:87 clk_branch_wait+0x144/0x15c<br />
...<br />
Call trace:<br />
clk_branch_wait+0x144/0x15c<br />
clk_branch2_enable+0x30/0x40<br />
clk_core_enable+0xd8/0x29c<br />
clk_enable+0x2c/0x4c<br />
vcodec_clks_enable.isra.0+0x94/0xd8 [venus_core]<br />
coreid_power_v4+0x464/0x628 [venus_core]<br />
vdec_start_streaming+0xc4/0x510 [venus_dec]<br />
vb2_start_streaming+0x6c/0x180 [videobuf2_common]<br />
vb2_core_streamon+0x120/0x1dc [videobuf2_common]<br />
vb2_streamon+0x1c/0x6c [videobuf2_v4l2]<br />
v4l2_m2m_ioctl_streamon+0x30/0x80 [v4l2_mem2mem]<br />
v4l_streamon+0x24/0x30 [videodev]<br />
<br />
using the out-of-tree sm8350/sc8280xp venus support. [1]<br />
<br />
Update also the sm8350/sc8280xp GDSC definitions so that the hw control<br />
mode can be changed at runtime as the venus driver now requires.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.11 (including) | 6.11.8 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.12:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.12:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.12:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.12:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.12:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.12:rc6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



