CVE-2024-42274: Revert "ALSA: firewire-lib: operate for period elapse event in process context"

Published Aug 17, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

Revert "ALSA: firewire-lib: operate for period elapse event in process context"

Commit 7ba5ca32fe6e ("ALSA: firewire-lib: operate for period elapse event in process context") removed the process context workqueue from amdtpdomainstreampcmpointer() and updatepcmpointers() to remove its overhead.

With RME Fireface 800, this lead to a regression since Kernels 5.14.0, causing an AB/BA deadlock competition for the substream lock with eventual system freeze under ALSA operation:

thread 0: (lock A) acquire substream lock by sndpcmstreamlockirq() in sndpcmstatus64() (lock B) wait for tasklet to finish by calling taskletunlockspinwait() in taskletdisableinatomic() in ohciflushisocompletions() of ohci.c

thread 1: (lock B) enter tasklet (lock A) attempt to acquire substream lock, waiting for it to be released: sndpcmstreamlockirqsave() in sndpcmperiodelapsed() in updatepcmpointers() in processctxpayloads() in processrxpackets() of amdtp-stream.c

? taskletunlockspinwait </NMI> <TASK> ohciflushisocompletions firewireohci amdtpdomainstreampcmpointer sndfirewirelib sndpcmupdatehwptr0 sndpcm sndpcmstatus64 sndpcm

? nativequeuedspinlockslowpath </NMI> <IRQ> rawspinlockirqsave sndpcmperiodelapsed sndpcm processrxpackets sndfirewirelib irqtargetcallback sndfirewirelib handleitpacket firewireohci contexttasklet firewireohci

Restore the process context work queue to prevent deadlock AB/BA deadlock competition for ALSA substream lock of sndpcmstreamlockirq() in sndpcmstatus64() and sndpcmstreamlockirqsave() in sndpcmperiodelapsed().

revert commit 7ba5ca32fe6e ("ALSA: firewire-lib: operate for period elapse event in process context")

Replace inline description to prevent future deadlock.

Affected Software

7 affected componentsFixes available
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Linux Linux kernel>=5.14<5.15.165
Linux Linux kernel>=5.16<6.1.104
Linux Linux kernel>=6.2<6.6.45
Linux Linux kernel>=6.7<6.10.4
Linux Linux kernel=6.11-rc1

Event History

Aug 17, 2024
CVE Published
via MITRE·08:54 AM
Data Sourced
via MITRE·08:54 AM
Description
Data Sourced
via NVD·09:15 AM
Description
Data Sourced
via NVD·09:15 AM
RemedySeverityWeaknessAffected Software
May 11, 2025
Data Sourced
via Ubuntu·06:24 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-42274?

CVE-2024-42274 has a severity rating that is determined by its impact on the system; specific details can be found in the vulnerability report.

2

How do I fix CVE-2024-42274?

To fix CVE-2024-42274, update your Linux kernel to one of the remedial versions specified in the vulnerability report.

3

What systems are affected by CVE-2024-42274?

CVE-2024-42274 affects specific versions of the Linux kernel, particularly those listed in the affected software section.

4

Is CVE-2024-42274 a remote vulnerability?

CVE-2024-42274's details regarding remote exploitation capabilities are outlined in its technical description.

5

What should I do if my system is running an affected version of CVE-2024-42274?

If your system is running an affected version, immediately apply the recommended updates to mitigate any potential risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203