CVE-2024-46702: thunderbolt: Mark XDomain as unplugged when router is removed

Published Sep 13, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: Mark XDomain as unplugged when router is removed

I noticed that when we do discrete host router NVM upgrade and it gets hot-removed from the PCIe side as a result of NVM firmware authentication, if there is another host connected with enabled paths we hang in tearing them down. This is due to fact that the Thunderbolt networking driver also tries to cleanup the paths and ends up blocking in tbdisconnectxdomainpaths() waiting for the domain lock.

However, at this point we already cleaned the paths in tbstop() so there is really no need for tbdisconnectxdomainpaths() to do that anymore. Furthermore it already checks if the XDomain is unplugged and bails out early so take advantage of that and mark the XDomain as unplugged when we remove the parent router.

Affected Software

15 affected componentsFixes available
Linux Linux kernel<5.10.225
Linux Linux kernel>=5.11<5.15.166
Linux Linux kernel>=5.16<6.1.107
Linux Linux kernel>=6.2<6.6.48
Linux Linux kernel>=6.7<6.10.7
Linux Linux kernel=6.11-rc1
Linux Linux kernel=6.11-rc2
Linux Linux kernel=6.11-rc3
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Microsoft cbl2 kernel 5.15.164.1-1
Microsoft azl3 kernel 6.6.47.1-1
Microsoft cbl2 kernel 5.15.164.1-1
Microsoft azl3 kernel 6.6.51.1-5
Microsoft cbl2 kernel 5.15.167.1-1

Event History

Sep 13, 2024
CVE Published
via MITRE·06:27 AM
Data Sourced
via MITRE·06:27 AM
Description
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityAffected Software
Oct 12, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Apr 29, 2025
Data Sourced
via Ubuntu·06:23 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-46702?

CVE-2024-46702 has a medium severity rating due to its impact on the Linux kernel's Thunderbolt functionality.

2

How do I fix CVE-2024-46702?

To resolve CVE-2024-46702, upgrade to the recommended Linux kernel versions such as 5.10.226-1 or later.

3

Which systems are affected by CVE-2024-46702?

CVE-2024-46702 affects various versions of the Linux kernel, particularly versions before 5.10.226 and those in the ranges specified for 6.x series.

4

Is CVE-2024-46702 exploitable remotely?

CVE-2024-46702 may allow an attacker with local access to exploit the vulnerability, but it is not classified as a remote exploit.

5

What components are impacted by CVE-2024-46702 in the Linux kernel?

CVE-2024-46702 specifically impacts the Thunderbolt controller functionality within the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203