CVE-2024-42129: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: leds: mlxreg: Use devm_mutex_init() for mutex initialization In this driver LEDs are registered using devm_led_classdev_register() so they are automatically unregistered after module's remove() is done. led_classdev_unregister() calls module's led_set_brightness() to turn off the LEDs and that callback uses mutex which was destroyed already in module's remove() so use devm API instead.

Affected products

  • Linux Linux Kernel: before 6.1.132 (fixed in 6.1.132); from 6.2, before 6.6.63 (fixed in 6.6.63); from 6.7, before 6.9.9 (fixed in 6.9.9)

Published 2024-07-30. Last modified 2026-06-17.