CVE-2024-41064
HIGH severity · CVSS 7.8
7.8CVSS HIGH
Summary
In the Linux kernel, the following vulnerability has been resolved: powerpc/eeh: avoid possible crash when edev->pdev changes If a PCI device is removed during eeh_pe_report_edev(), edev->pdev will change and can cause a crash, hold the PCI rescan/remove lock while taking a copy of edev->pdev->bus.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://git.kernel.org/stable/c/033c51dfdbb6b79ab43fb3587276fa82d0a329e1 ↗
Additional information
- NVD record
- https://git.kernel.org/stable/c/033c51dfdbb6b79ab43fb3587276fa82d0a329e1Patch
- https://git.kernel.org/stable/c/428d940a8b6b3350b282c14d3f63350bde65c48bPatch
- https://git.kernel.org/stable/c/4bc246d2d60d071314842fa448faa4ed39082affPatch
- https://git.kernel.org/stable/c/4fad7fef847b6028475dd7b4c14fcb82b3e51274Patch
- https://git.kernel.org/stable/c/8836e1bf5838ac6c08760e0a2dd7cf6410aa7ff3Patch
- https://git.kernel.org/stable/c/a1216e62d039bf63a539bbe718536ec789a853ddPatch
- https://git.kernel.org/stable/c/f23c3d1ca9c4b2d626242a4e7e1ec1770447f7b5Patch