CVE-2024-41036: net: ks8851: Fix deadlock with the SPI chip variant

Published Jul 29, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: ks8851: Fix deadlock with the SPI chip variant

When SMP is enabled and spinlocks are actually functional then there is a deadlock with the 'statelock' spinlock between ks8851startxmitspi and ks8851irq:

watchdog: BUG: soft lockup - CPU#0 stuck for 27s! call trace: queuedspinlockslowpath+0x100/0x284 dorawspinlock+0x34/0x44 ks8851startxmitspi+0x30/0xb8 ks8851startxmit+0x14/0x20 netdevstartxmit+0x40/0x6c devhardstartxmit+0x6c/0xbc schdirectxmit+0xa4/0x22c qdiscrun+0x138/0x3fc qdiscrun+0x24/0x3c nettxaction+0xf8/0x130 handlesoftirqs+0x1ac/0x1f0 dosoftirq+0x14/0x20 dosoftirq+0x10/0x1c callonirqstack+0x3c/0x58 dosoftirqownstack+0x1c/0x28 irqexitrcu+0x54/0x9c irqexitrcu+0x10/0x1c el1interrupt+0x38/0x50 el1h64irqhandler+0x18/0x24 el1h64irq+0x64/0x68 netifschedule+0x6c/0x80 netiftxwakequeue+0x38/0x48 ks8851irq+0xb8/0x2c8 irqthreadfn+0x2c/0x74 irqthread+0x10c/0x1b0 kthread+0xc8/0xd8 retfromfork+0x10/0x20

This issue has not been identified earlier because tests were done on a device with SMP disabled and so spinlocks were actually NOPs.

Now use spin(un)lockbh for TX queue related locking to avoid execution of softirq work synchronously that would lead to a deadlock.

Affected Software

12 affected componentsFixes available
Linux Linux kernel>=6.1.70<6.1.100
Linux Linux kernel>=6.6.9<6.6.41
Linux Linux kernel>=6.7<6.9.10
Linux Linux kernel=6.10-rc1
Linux Linux kernel=6.10-rc2
Linux Linux kernel=6.10-rc3
Linux Linux kernel=6.10-rc4
Linux Linux kernel=6.10-rc5
Linux Linux kernel=6.10-rc6
Linux Linux kernel=6.10-rc7
debian/linux<=5.10.223-1, <=5.10.234-1
6.1.129-16.1.135-16.12.22-16.12.25-1
debian/linux-6.1
6.1.129-1~deb11u1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1
  2. Upgrade

    Upgrade debian/linux-6.1 to a version that resolves this vulnerability.

    Fixed in 6.1.129-1~deb11u1

Event History

Jul 29, 2024
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverity
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 1, 2025
Data Sourced
via Ubuntu·12:32 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-41036?

CVE-2024-41036 has a moderate severity rating due to its potential for deadlock in the kernel.

2

What systems are affected by CVE-2024-41036?

CVE-2024-41036 affects various versions of the Linux kernel, including versions ranging from 6.1.70 to 6.6.41 and any 6.10 release candidates.

3

How do I fix CVE-2024-41036?

To fix CVE-2024-41036, users should update to patched kernel versions such as 6.1.123-1 or 6.12.12-1.

4

What is the impact of not addressing CVE-2024-41036?

Failure to address CVE-2024-41036 may result in system instability or deadlocks during operation.

5

Is CVE-2024-41036 related to specific hardware?

Yes, CVE-2024-41036 specifically pertains to the ks8851 SPI chip variant in the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203