CVE-2024-50210
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/11/2024
Last modified:
03/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
posix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime()<br />
<br />
If get_clock_desc() succeeds, it calls fget() for the clockid&#39;s fd,<br />
and get the clk->rwsem read lock, so the error path should release<br />
the lock to make the lock balance and fput the clockid&#39;s fd to make<br />
the refcount balance and release the fd related resource.<br />
<br />
However the below commit left the error path locked behind resulting in<br />
unbalanced locking. Check timespec64_valid_strict() before<br />
get_clock_desc() to fix it, because the "ts" is not changed<br />
after that.<br />
<br />
[pabeni@redhat.com: fixed commit message typo]
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.10.228 (including) | 5.11 (excluding) |
| cpe:2.3:o:linux:linux_kernel:5.15.169:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.1.114:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.6.58:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.11.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.12:rc4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1ba33b327c3f88a7baee598979d73ab5b44d41cc
- https://git.kernel.org/stable/c/5f063bbf1ee6b01611c016b54e050a41506eb794
- https://git.kernel.org/stable/c/6e62807c7fbb3c758d233018caf94dfea9c65dbd
- https://git.kernel.org/stable/c/a8219446b95a859488feaade674d13f9efacfa32
- https://git.kernel.org/stable/c/b27330128eca25179637c1816d5a72d6cc408c66
- https://git.kernel.org/stable/c/c7fcfdba35abc9f39b83080c2bce398dad13a943
- https://git.kernel.org/stable/c/d005400262ddaf1ca1666bbcd1acf42fe81d57ce
- https://git.kernel.org/stable/c/e56e0ec1b79f5a6272c6e78b36e9d593aa0449af
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html



