CVE-2024-40965

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-40965
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-40965.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-40965
Downstream
Related
Published
2024-07-12T13:15:18Z
Modified
2025-08-09T20:01:26Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

i2c: lpi2c: Avoid calling clkgetrate during transfer

Instead of repeatedly calling clkgetrate for each transfer, lock the clock rate and cache the value. A deadlock has been observed while adding tlv320aic32x4 audio codec to the system. When this clock provider adds its clock, the clk mutex is locked already, it needs to access i2c, which in return needs the mutex for clkgetrate as well.

References

Affected packages