CVE-2024-50249: ACPI: CPPC: Make rmw_lock a raw_spin_lock
ACPI: CPPC: Make rmwlock a rawspinlock
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.64.2-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.15.173.1-1 - Configuration
Update ACPI CPPC's rmw_lock to use a raw_spin_lock so the wait-type order is correct (as described: "update rmw_lock to a raw spinlock").
Linux kernel ACPI CPPC cpc_ptr->rmw_lock lock type = raw_spin_lock
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50249?
The severity of CVE-2024-50249 is categorized at a level that indicates a potentially significant impact on affected systems.
How do I fix CVE-2024-50249?
To fix CVE-2024-50249, update your Linux kernel to a version that includes the patch, such as 5.10.223-1 or 6.12.12-1.
Which Linux kernel versions are affected by CVE-2024-50249?
CVE-2024-50249 affects several Linux kernel versions including 5.15.168 to 5.15.171, 6.1.113 to 6.1.116, and 6.6.54 to 6.6.60.
Is there a workaround for CVE-2024-50249 if I'm unable to update my kernel?
Currently, there are no known workarounds for CVE-2024-50249 other than upgrading to a patched version of the kernel.
What types of systems are vulnerable to CVE-2024-50249?
Systems running vulnerable versions of the Linux kernel are at risk of being affected by CVE-2024-50249.