#VU94281 Improper locking in Linux kernel


Published: 2024-07-13

Vulnerability identifier: #VU94281

Vulnerability risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-40916

CWE-ID: CWE-667

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the hdmi_get_modes() function in drivers/gpu/drm/exynos/exynos_hdmi.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/e23f2eaf51ecb6ab4ceb770e747d50c1db2eb222
http://git.kernel.org/stable/c/4dfffb50316c761c59386c9b002a10ac6d7bb6c9
http://git.kernel.org/stable/c/6d6bb258d886e124e5a5328e947b36fdcb3a6028
http://git.kernel.org/stable/c/c3ca24dfe9a2b3f4e8899af108829b0f4b4b15ec
http://git.kernel.org/stable/c/35bcf16b4a28c10923ff391d14f6ed0ae471ee5f
http://git.kernel.org/stable/c/510a6c0dfa6ec61d07a4b64698d8dc60045bd632
http://git.kernel.org/stable/c/799d4b392417ed6889030a5b2335ccb6dcf030ab


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability