CVE-2024-42140: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: riscv: kexec: Avoid deadlock in kexec crash path If the kexec crash code is called in the interrupt context, the machine_kexec_mask_interrupts() function will trigger a deadlock while trying to acquire the irqdesc spinlock and then deactivate irqchip in irq_set_irqchip_state() function. Unlike arm64, riscv only requires irq_eoi handler to complete EOI and keeping irq_set_irqchip_state() will only leave this possible deadlock without any use. So we simply remove it.

Affected products

  • Linux Linux Kernel: from 5.15.82, before 5.15.163 (fixed in 5.15.163); from 6.0.12, before 6.1.98 (fixed in 6.1.98); from 6.2, before 6.6.39 (fixed in 6.6.39); from 6.7, before 6.9.9 (fixed in 6.9.9)

Published 2024-07-30. Last modified 2026-06-17.