|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: REJECTED: CVE-2024-26650: kernel: platform/x86: deadlock when rescan is triggered by /sys/bus/pci/rescan | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | SMASH SMASH <smash_bz> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED INVALID | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | andrea.mattiazzo, carlos.lopez, gabriel.bertazi |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/399016/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2024-26650:4.4:(AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
SMASH SMASH
2024-03-27 10:27:59 UTC
Already fixed in SLE15-SP6-GA and newer. Older branches are not affected. (In reply to Carlos López from comment #1) > Already fixed in SLE15-SP6-GA and newer. Older branches are not affected. This was fixed by 5913320eb0b3 ("platform/x86: p2sb: Allow p2sb_bar() calls during PCI device probe") in 6.8 and from a quick look, I don't see it backported in SLE15-SP6-GA. This seems to be maintained by Takashi. Takashi, can you please take look to confirm? Feel free to reassign if there is a better person to handle it. (In reply to Gabriel Krisman Bertazi from comment #2) > (In reply to Carlos López from comment #1) > > Already fixed in SLE15-SP6-GA and newer. Older branches are not affected. > > This was fixed by 5913320eb0b3 ("platform/x86: p2sb: Allow p2sb_bar() calls > during PCI device probe") in 6.8 and from a quick look, I don't see it > backported in SLE15-SP6-GA. It's in SLE15-SP6 branch. As it's CVSS 4.4, we don't need for GA. > This seems to be maintained by Takashi. Takashi, can you please take look to > confirm? Feel free to reassign if there is a better person to handle it. I updated the patch reference on SLE15-SP6 branch. Reassigned back to security team. |