Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-46797— powerpc/qspinlock: Fix deadlock in MCS queue

AI Predicted 7.8 Difficulty: Moderate EPSS 0.16% · P6

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinux84990b169557428c318df87b7836cd15f65b62dc< d84ab6661e8d09092de9b034b016515ef9b66085affected
84990b169557428c318df87b7836cd15f65b62dc< f06af737e4be28c0e926dc25d5f0a111da4e2987affected
84990b169557428c318df87b7836cd15f65b62dc< 734ad0af3609464f8f93e00b6c0de1e112f44559affected
6.2affected
< 6.2unaffected
6.6.51≤ 6.6.*unaffected
6.10.10≤ 6.10.*unaffected
6.11≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-46797

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
powerpc/qspinlock: Fix deadlock in MCS queue
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: powerpc/qspinlock: Fix deadlock in MCS queue If an interrupt occurs in queued_spin_lock_slowpath() after we increment qnodesp->count and before node->lock is initialized, another CPU might see stale lock values in get_tail_qnode(). If the stale lock value happens to match the lock on that CPU, then we write to the "next" pointer of the wrong qnode. This causes a deadlock as the former CPU, once it becomes the head of the MCS queue, will spin indefinitely until it's "next" pointer is set by its successor in the queue. Running stress-ng on a 16 core (16EC/16VP) shared LPAR, results in occasional lockups similar to the following: $ stress-ng --all 128 --vm-bytes 80% --aggressive \ --maximize --oomable --verify --syslog \ --metrics --times --timeout 5m watchdog: CPU 15 Hard LOCKUP ...... NIP [c0000000000b78f4] queued_spin_lock_slowpath+0x1184/0x1490 LR [c000000001037c5c] _raw_spin_lock+0x6c/0x90 Call Trace: 0xc000002cfffa3bf0 (unreliable) _raw_spin_lock+0x6c/0x90 raw_spin_rq_lock_nested.part.135+0x4c/0xd0 sched_ttwu_pending+0x60/0x1f0 __flush_smp_call_function_queue+0x1dc/0x670 smp_ipi_demux_relaxed+0xa4/0x100 xive_muxed_ipi_action+0x20/0x40 __handle_irq_event_percpu+0x80/0x240 handle_irq_event_percpu+0x2c/0x80 handle_percpu_irq+0x84/0xd0 generic_handle_irq+0x54/0x80 __do_irq+0xac/0x210 __do_IRQ+0x74/0xd0 0x0 do_IRQ+0x8c/0x170 hardware_interrupt_common_virt+0x29c/0x2a0 --- interrupt: 500 at queued_spin_lock_slowpath+0x4b8/0x1490 ...... NIP [c0000000000b6c28] queued_spin_lock_slowpath+0x4b8/0x1490 LR [c000000001037c5c] _raw_spin_lock+0x6c/0x90 --- interrupt: 500 0xc0000029c1a41d00 (unreliable) _raw_spin_lock+0x6c/0x90 futex_wake+0x100/0x260 do_futex+0x21c/0x2a0 sys_futex+0x98/0x270 system_call_exception+0x14c/0x2f0 system_call_vectored_common+0x15c/0x2ec The following code flow illustrates how the deadlock occurs. For the sake of brevity, assume that both locks (A and B) are contended and we call the queued_spin_lock_slowpath() function. CPU0 CPU1 ---- ---- spin_lock_irqsave(A) | spin_unlock_irqrestore(A) | spin_lock(B) | | | ▼ | id = qnodesp->count++; | (Note that nodes[0].lock == A) | | | ▼ | Interrupt | (happens before "nodes[0].lock = B") | | | ▼ | spin_lock_irqsave(A) | | | ▼ | id = qnodesp->count++ | nodes[1].lock = A | | | ▼ | Tail of MCS queue | | spin_lock_irqsave(A) ▼ | Head of MCS queue ▼ | CPU0 is previous tail ▼ | Spin indefinitely ▼ (until "nodes[1].next != NULL") prev = get_tail_qnode(A, CPU0) | ▼ prev == &qnodes[CPU0].nodes[0] (as qnodes ---truncated---
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于存在死锁问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 84990b169557428c318df87b7836cd15f65b62dc ~ d84ab6661e8d09092de9b034b016515ef9b66085 -
LinuxLinux 6.2 -

II. Public POCs for CVE-2024-46797

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-46797

登录查看更多情报信息。

Same Patch Batch · Linux · 2024-09-18 · 85 CVEs total

CVE-2024-467179.8 CRITICALnet/mlx5e: SHAMPO, Fix incorrect page release
CVE-2024-467369.8 CRITICALsmb: client: fix double put of @cfile in smb2_rename_path()
CVE-2024-467969.8 CRITICALsmb: client: fix double put of @cfile in smb2_set_path_size()
CVE-2024-467558.8 HIGHwifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
CVE-2024-467507.8 HIGHPCI: Add missing bridge lock to pci_bus_lock()
CVE-2024-467877.8 HIGHuserfaultfd: fix checks for huge PMDs
CVE-2024-467167.8 HIGHdmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor
CVE-2024-467347.8 HIGHbtrfs: fix race between direct IO write and fsync when using same fd
CVE-2024-467387.8 HIGHVMCI: Fix use-after-free when removing resource in vmci_resource_remove()
CVE-2024-467407.8 HIGHbinder: fix UAF caused by offsets overwrite
CVE-2024-467817.8 HIGHnilfs2: fix missing cleanup on rollforward recovery error
CVE-2024-467467.8 HIGHHID: amd_sfh: free driver_data after destroying hid device
CVE-2024-467807.8 HIGHnilfs2: protect references to superblock parameters exposed in sysfs
CVE-2024-467417.8 HIGHmisc: fastrpc: Fix double free of 'buf' in error path
CVE-2024-467517.8 HIGHbtrfs: don't BUG_ON() when 0 reference count at btrfs_lookup_extent_info()
CVE-2024-467777.8 HIGHudf: Avoid excessive partition lengths
CVE-2024-467547.8 HIGHbpf: Remove tst_run from lwt_seg6local_prog_ops.
CVE-2024-467627.8 HIGHxen: privcmd: Fix possible access to a freed kirqfd instance
CVE-2024-467657.8 HIGHice: protect XDP configuration with a mutex
CVE-2024-467717.8 HIGHcan: bcm: Remove proc entry when dev is unregistered.

Showing top 20 of 85 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-46797

No comments yet


Leave a comment