CVE-2024-44957
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/09/2024
Last modified:
06/09/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
xen: privcmd: Switch from mutex to spinlock for irqfds<br />
<br />
irqfd_wakeup() gets EPOLLHUP, when it is called by<br />
eventfd_release() by way of wake_up_poll(&ctx->wqh, EPOLLHUP), which<br />
gets called under spin_lock_irqsave(). We can&#39;t use a mutex here as it<br />
will lead to a deadlock.<br />
<br />
Fix it by switching over to a spin lock.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.46 (excluding) | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.10.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



