CVE-2024-27021

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-27021
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-27021.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-27021
Downstream
Published
2024-05-01T05:30:21Z
Modified
2025-10-09T06:52:00.199943Z
Summary
r8169: fix LED-related deadlock on module removal
Details

In the Linux kernel, the following vulnerability has been resolved:

r8169: fix LED-related deadlock on module removal

Binding devmledclassdev_register() to the netdev is problematic because on module removal we get a RTNL-related deadlock. Fix this by avoiding the device-managed LED functions.

Note: We can safely call ledclassdevunregister() for a LED even if registering it failed, because ledclassdevunregister() detects this and is a no-op in this case.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
18764b883e157e28126b54e7d4ba9dd487d5bf54
Fixed
53d986f39acd8ea11c9e460732bfa5add66360d9
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
18764b883e157e28126b54e7d4ba9dd487d5bf54
Fixed
19fa4f2a85d777a8052e869c1b892a2f7556569d

Affected versions

v6.*

v6.7
v6.7-rc6
v6.7-rc7
v6.7-rc8
v6.8
v6.8-rc1
v6.8-rc2
v6.8-rc3
v6.8-rc4
v6.8-rc5
v6.8-rc6
v6.8-rc7
v6.8.1
v6.8.2
v6.8.3
v6.8.4
v6.8.5
v6.8.6
v6.8.7
v6.9-rc1
v6.9-rc2

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.8.8