Removing Useless Locks in usbtv_video_free() to Prevent Deadlocks
CVE-2024-27072

5.5MEDIUM

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
1 May 2024

What is CVE-2024-27072?

In the Linux kernel, the following vulnerability has been resolved:

media: usbtv: Remove useless locks in usbtv_video_free()

Remove locks calls in usbtv_video_free() because are useless and may led to a deadlock as reported here: https://syzkaller.appspot.com/x/bisect.txt?x=166dc872180000 Also remove usbtv_stop() call since it will be called when unregistering the device.

Before 'c838530d230b' this issue would only be noticed if you disconnect while streaming and now it is noticeable even when disconnecting while not streaming.

[hverkuil: fix minor spelling mistake in log message]

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux f3d27f34fdd7701e499617d2c1d94480a98f6d07 < 4ec4641df57cbdfdc51bb4959afcdbcf5003ddb9

Linux f3d27f34fdd7701e499617d2c1d94480a98f6d07

Linux f3d27f34fdd7701e499617d2c1d94480a98f6d07

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.