CVE-2024-57949

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-57949
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-57949.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-57949
Downstream
Published
2025-02-09T12:15:28Z
Modified
2025-08-09T20:01:28Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

irqchip/gic-v3-its: Don't enable interrupts in itsirqsetvcpuaffinity()

The following call-chain leads to enabling interrupts in a nested interrupt disabled section:

irqsetvcpuaffinity() irqgetdesclock() rawspinlockirqsave() <--- Disable interrupts itsirqsetvcpuaffinity() guard(rawspinlockirq) <--- Enables interrupts when leaving the guard() irqputdescunlock() <--- Warns because interrupts are enabled

This was broken in commit b97e8a2f7130, which replaced the original rawspin[un]lock() pair with guard(rawspinlockirq).

Fix the issue by using guard(raw_spinlock).

[ tglx: Massaged change log ]

References

Affected packages