CVE-2024-38780: dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
Published Jun 21, 2024
·Updated
dma-buf/sw-sync: don't enable IRQ from syncprintobj()
Affected Software
15 affected componentsFixes available
Linux Linux kernel<4.14
Linux Linux kernel>=4.19<4.19.316
Linux Linux kernel>=5.4<5.4.278
Linux Linux kernel>=5.10<5.10.219
Linux Linux kernel>=5.15<5.15.161
Linux Linux kernel>=6.1<6.1.93
Linux Linux kernel>=6.6<6.6.33
Linux Linux kernel>=6.9<6.9.4
Linux Linux kernel=6.10.0-rc1
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Microsoft cbl2 kernel 5.15.160.1-1
Microsoft cbl2 kernel 5.15.162.2-1
Microsoft cbl2 kernel 5.15.160.1-1
Microsoft azl3 kernel 6.6.29.1-5
Microsoft azl3 kernel 6.6.35.1-4
Remediation
Event History
Jun 21, 2024
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
Description
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 5, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Aug 8, 2024
Data Sourced
via Launchpad·11:30 PM
Description
Apr 27, 2025
Data Sourced
via Ubuntu·12:31 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-38780?
The severity of CVE-2024-38780 is classified based on its potential impact on system stability and security, requiring evaluation by system administrators.
2
How do I fix CVE-2024-38780?
To fix CVE-2024-38780, upgrade the Linux kernel to one of the secure versions such as 5.10.223-1 or above, as well as other specified patched versions.
3
What systems are affected by CVE-2024-38780?
CVE-2024-38780 affects multiple versions of the Linux kernel, specifically versions prior to 4.14 and between 4.19.0 and 6.9.4.
4
Can CVE-2024-38780 be exploited remotely?
CVE-2024-38780 may allow local escalation of privileges, but it is typically not exploitable remotely without prior access.
5
What are the potential consequences of CVE-2024-38780 if left unpatched?
If left unpatched, CVE-2024-38780 can lead to system instability and potential unauthorized access by local users.