CVE-2024-46868: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: Fix deadlock in qcuefi_acquire() If the __qcuefi pointer is not set, then in the original code, we would hold onto the lock. That means that if we tried to set it later, then it would cause a deadlock. Drop the lock on the error path. That's what all the callers are expecting.

Affected products

  • Linux Linux Kernel: from 6.7, before 6.10.11 (fixed in 6.10.11); version 6.11 only

Published 2024-09-27. Last modified 2026-06-17.