CVE-2024-40966: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: tty: add the option to have a tty reject a new ldisc ... and use it to limit the virtual terminals to just N_TTY. They are kind of special, and in particular, the "con_write()" routine violates the "writes cannot sleep" rule that some ldiscs rely on. This avoids the BUG: sleeping function called from invalid context at kernel/printk/printk.c:2659 when N_GSM has been attached to a virtual console, and gsmld_write() calls con_write() while holding a spinlock, and con_write() then tries to get the console lock.

Affected products

  • Linux Linux Kernel: before 6.1.96 (fixed in 6.1.96); from 6.2, before 6.6.36 (fixed in 6.6.36); from 6.7, before 6.9.7 (fixed in 6.9.7)

Published 2024-07-12. Last modified 2026-06-17.