目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-42290— Linux kernel 安全漏洞

AI 预测 3.7 利用难度: 理论可行 EPSS 0.23% · P14

可能的 ATT&CK 技术 1AI

T1564.004 · NTFS File Attributes

影响版本矩阵 16

厂商产品版本范围状态
LinuxLinux0136afa08967f6e160b9b4e85a7a70e4180a8333< a590e8dea3df2639921f874d763be961dd74e8f9affected
0136afa08967f6e160b9b4e85a7a70e4180a8333< 3a2884a44e5cda192df1b28e9925661f79f599a1affected
0136afa08967f6e160b9b4e85a7a70e4180a8333< fa1803401e1c360efe6342fb41d161cc51748a11affected
0136afa08967f6e160b9b4e85a7a70e4180a8333< 58c56735facb225a5c46fa4b8bbbe7f31d1cb894affected
0136afa08967f6e160b9b4e85a7a70e4180a8333< 21bd3f9e7f924cd2fc892a484e7a50c7e1847565affected
0136afa08967f6e160b9b4e85a7a70e4180a8333< f8ae38f1dfe652779c7c613facbc257cec00ac44affected
0136afa08967f6e160b9b4e85a7a70e4180a8333< 33b1c47d1fc0b5f06a393bb915db85baacba18eaaffected
5.0affected
… +8 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-42290 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
irqchip/imx-irqsteer: Handle runtime power management correctly
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: irqchip/imx-irqsteer: Handle runtime power management correctly The power domain is automatically activated from clk_prepare(). However, on certain platforms like i.MX8QM and i.MX8QXP, the power-on handling invokes sleeping functions, which triggers the 'scheduling while atomic' bug in the context switch path during device probing: BUG: scheduling while atomic: kworker/u13:1/48/0x00000002 Call trace: __schedule_bug+0x54/0x6c __schedule+0x7f0/0xa94 schedule+0x5c/0xc4 schedule_preempt_disabled+0x24/0x40 __mutex_lock.constprop.0+0x2c0/0x540 __mutex_lock_slowpath+0x14/0x20 mutex_lock+0x48/0x54 clk_prepare_lock+0x44/0xa0 clk_prepare+0x20/0x44 imx_irqsteer_resume+0x28/0xe0 pm_generic_runtime_resume+0x2c/0x44 __genpd_runtime_resume+0x30/0x80 genpd_runtime_resume+0xc8/0x2c0 __rpm_callback+0x48/0x1d8 rpm_callback+0x6c/0x78 rpm_resume+0x490/0x6b4 __pm_runtime_resume+0x50/0x94 irq_chip_pm_get+0x2c/0xa0 __irq_do_set_handler+0x178/0x24c irq_set_chained_handler_and_data+0x60/0xa4 mxc_gpio_probe+0x160/0x4b0 Cure this by implementing the irq_bus_lock/sync_unlock() interrupt chip callbacks and handle power management in them as they are invoked from non-atomic context. [ tglx: Rewrote change log, added Fixes tag ]
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 0136afa08967f6e160b9b4e85a7a70e4180a8333 ~ a590e8dea3df2639921f874d763be961dd74e8f9 -
LinuxLinux 5.0 -

二、漏洞 CVE-2024-42290 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-42290 的情报信息

登录查看更多情报信息。

CVE-2024-42290 其他参考 (7)

同批安全公告 · Linux · 2024-08-17 · 共 109 条

CVE-2024-43820Linux kernel 安全漏洞
CVE-2024-43833Linux kernel 安全漏洞
CVE-2024-43831Linux kernel 安全漏洞
CVE-2024-43832Linux kernel 安全漏洞
CVE-2024-43830Linux kernel 安全漏洞
CVE-2024-43829Linux kernel 安全漏洞
CVE-2024-43828Linux kernel 安全漏洞
CVE-2024-43827Linux kernel 安全漏洞
CVE-2024-43826Linux kernel 安全漏洞
CVE-2024-43825Linux kernel 安全漏洞
CVE-2024-43823Linux kernel 安全漏洞
CVE-2024-43824Linux kernel 安全漏洞
CVE-2024-43822Linux kernel 安全漏洞
CVE-2024-43821Linux kernel 安全漏洞
CVE-2024-42318Linux kernel 安全漏洞
CVE-2024-42321Linux kernel 安全漏洞
CVE-2024-42320Linux kernel 安全漏洞
CVE-2024-42319Linux kernel 安全漏洞
CVE-2024-42322Linux kernel 安全漏洞
CVE-2024-42317Linux kernel 安全漏洞

显示前 20 条,共 109 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-42290

暂无评论


发表评论