CVE-2024-35819: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: Use raw spinlock for cgr_lock smp_call_function always runs its callback in hard IRQ context, even on PREEMPT_RT, where spinlocks can sleep. So we need to use a raw spinlock for cgr_lock to ensure we aren't waiting on a sleeping task. Although this bug has existed for a while, it was not apparent until commit ef2a8d5478b9 ("net: dpaa: Adjust queue depth on rate change") which invokes smp_call_function_single via qman_update_cgr_safe every time a link goes up or down.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 4.9.92, before 4.10 (fixed in 4.10); from 4.14.32, before 4.15 (fixed in 4.15); from 4.15.15, before 4.16 (fixed in 4.16); from 4.16.1, before 4.19.312 (fixed in 4.19.312); from 4.20, before 5.4.274 (fixed in 5.4.274); from 5.5, before 5.10.215 (fixed in 5.10.215); …

Published 2024-05-17. Last modified 2026-06-17.