CVE-2024-46702

Updated: 2024-09-21 05:02:18.251674

Description:

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Mark XDomain as unplugged when router is removed I noticed that when we do discrete host router NVM upgrade and it gets hot-removed from the PCIe side as a result of NVM firmware authentication, if there is another host connected with enabled paths we hang in tearing them down. This is due to fact that the Thunderbolt networking driver also tries to cleanup the paths and ends up blocking in tb_disconnect_xdomain_paths() waiting for the domain lock. However, at this point we already cleaned the paths in tb_stop() so there is really no need for tb_disconnect_xdomain_paths() to do that anymore. Furthermore it already checks if the XDomain is unplugged and bails out early so take advantage of that and mark the XDomain as unplugged when we remove the parent router.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2024-09-23 05:22:40
AlmaLinux 9.2 FIPS kernel 5.14.0 5.5 MEDIUM Ignored 2024-09-23 05:22:40
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2024-09-23 05:22:42
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2024-09-23 05:22:40
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2024-09-23 05:22:40
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2024-09-23 05:22:40
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2024-09-23 05:22:39
CloudLinux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2024-09-23 05:22:40
CloudLinux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2024-09-23 05:22:39
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2024-09-23 05:22:40
Total: 14