CVE-2024-35786: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix stale locked mutex in nouveau_gem_ioctl_pushbuf If VM_BIND is enabled on the client the legacy submission ioctl can't be used, however if a client tries to do so regardless it will return an error. In this case the clients mutex remained unlocked leading to a deadlock inside nouveau_drm_postclose or any other nouveau ioctl call.

Affected products

  • Linux Linux Kernel: from 6.6, before 6.6.24 (fixed in 6.6.24); from 6.7, before 6.7.12 (fixed in 6.7.12); version 6.8 only

Published 2024-05-17. Last modified 2026-06-17.