CVE-2024-27000: serial: mxs-auart: add spinlock around changing cts state
In the Linux kernel, the following vulnerability has been resolved:
serial: mxs-auart: add spinlock around changing cts state
The uarthandlectschange() function in serialcore expects the caller to hold uport->lock. For example, I have seen the below kernel splat, when the Bluetooth driver is loaded on an i.MX28 board.
[ 85.119255] ------------[ cut here ]------------ [ 85.124413] WARNING: CPU: 0 PID: 27 at /drivers/tty/serial/serialcore.c:3453 uarthandlectschange+0xb4/0xec [ 85.134694] Modules linked in: hciuart bluetooth ecdhgeneric ecc wlcoresdio configfs [ 85.143314] CPU: 0 PID: 27 Comm: kworker/u3:0 Not tainted 6.6.3-00021-gd62a2f068f92 #1 [ 85.151396] Hardware name: Freescale MXS (Device Tree) [ 85.156679] Workqueue: hci0 hcipoweron [bluetooth] (...) [ 85.191765] uarthandlectschange from mxsauartirqhandle+0x380/0x3f4 [ 85.198787] mxsauartirqhandle from handleirqeventpercpu+0x88/0x210 (...)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27000?
CVE-2024-27000 has a severity rating that indicates a potential risk in the Linux kernel related to improper handling of the cts state in the serial subsystem.
How do I fix CVE-2024-27000?
To fix CVE-2024-27000, update to the patched versions of the Linux kernel such as 5.10.223-1, 6.1.123-1, or 6.12.11-1.
Which versions of Linux are affected by CVE-2024-27000?
CVE-2024-27000 affects several versions including 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.10-1, and 6.12.11-1.
What components are involved in CVE-2024-27000?
CVE-2024-27000 involves the serial subsystem in the Linux kernel, specifically the uart_handle_cts_change() function.
Is CVE-2024-27000 resolved?
Yes, CVE-2024-27000 has been resolved in recent updates of the Linux kernel.