CVE-2024-26691

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-26691
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26691.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26691
Downstream
Related
Published
2024-04-03T15:15:52Z
Modified
2025-08-09T20:01:26Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Fix circular locking dependency

The rule inside kvm enforces that the vcpu->mutex is taken inside kvm->lock. The rule is violated by the pkvmcreatehypvm() which acquires the kvm->lock while already holding the vcpu->mutex lock from kvmvcpuioctl(). Avoid the circular locking dependency altogether by protecting the hyp vm handle with the configlock, much like we already do for other forms of VM-scoped data.

References

Affected packages