SB2024110581 - Improper locking in Linux kernel ufs core driver
Published: November 5, 2024 Updated: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2024-50098)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the ufshcd_wl_shutdown() function in drivers/ufs/core/ufshcd.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/7de759fceacff5660abf9590d11114215a9d5f3c
- https://git.kernel.org/stable/c/7bd9af254275fad7071d85f04616560deb598d7d
- https://git.kernel.org/stable/c/7774d23622416dbbbdb21bf342b3f0d92cf1dc0f
- https://git.kernel.org/stable/c/19a198b67767d952c8f3d0cf24eb3100522a8223
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.114
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.11.5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.58