CVE-2024-26934·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix deadlock in usb_deauthorize_interface() Among the attribute file callback routines in drivers/usb/core/sysfs.c, the interface_authorized_store() function is the only one which acquires a device lock on an ancestor device: It calls usb_deauthorize_interface(), which locks the interface's parent USB device. The will lead to deadlock if another process already owns that lock and tries to remove the interface, whether through a configuration change or because the device has been disconnected. As part of the removal procedure, device_del() waits for all ongoing sysfs attribute callbacks to complete. But usb_deauthorize_interface() can't complete until the device lock has been released, and the lock won't be released until the removal has finished. The mechanism provided by sysfs to prevent this kind of deadlock is to use the sysfs_break_active_protection() function, which tells sysfs not to wait for the attribute callback. Reported-and-tested by: Yue Sun <samsun1006219@gmail.com> Reported by: xingwei lee <xrivendell7@gmail.com>
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.8.3
- Published
- 2024-05-01
Affected versions
From: 6.8.0
Until: 6.8.3
Fixed in: 6.8.3
How to fix this CVE
Update your Linux kernel to version 6.8.3 or later to resolve a critical deadlock vulnerability in USB device authorization handling. This patch prevents system hangs when USB interface removal occurs concurrently with sysfs attribute modifications. Apply the update immediately using your distribution's package manager, followed by a system reboot to activate the patched kernel.
sudo dnf update kernel kernel-devel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check current kernel version with 'uname -r' and compare against 6.8.0-6.8.2 range
- Step 2: Verify USB subsystem is active by checking 'lsmod | grep usbcore' and 'cat /sys/kernel/debug/usb/devices'
- Step 3: Search system logs for deadlock indicators with 'sudo dmesg | grep -i "usb\|deadlock\|authorization"' and 'sudo journalctl -u kernel | grep -i deadlock'
- Step 4: Confirm patched kernel is running after reboot by verifying 'uname -r' shows version 6.8.3 or later, and check patch presence with 'git log --oneline | grep -i "usb.*deadlock" 2>/dev/null || echo "Patch status verification requires kernel source access"'
FAQ
What is CVE-2024-26934?
CVE-2024-26934 is a Linux kernel deadlock vulnerability in the USB core subsystem where concurrent sysfs attribute modifications and device removal operations can cause system hangs. The flaw exists in the usb_deauthorize_interface() function which improperly acquires ancestor device locks without proper deadlock protection mechanisms.
Is CVE-2024-26934 being actively exploited?
No, CVE-2024-26934 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. However, it can be triggered locally by unprivileged users with access to USB sysfs attributes.
What versions of Kernel are affected by CVE-2024-26934?
Linux kernel versions 6.8.0 through 6.8.2 are vulnerable. The vulnerability was patched in kernel version 6.8.3 and all subsequent releases.
How do I check if my server is vulnerable to CVE-2024-26934?
Run 'uname -r' to display your kernel version. If the output shows 6.8.0, 6.8.1, or 6.8.2, your system is vulnerable. Versions 6.8.3 or higher are patched.
Does Defensia detect CVE-2024-26934?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2024-26934 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/07acf979da33c721357ff27129edf74c23c036c6
- https://git.kernel.org/stable/c/122a06f1068bf5e39089863f4f60b1f5d4273384
- https://git.kernel.org/stable/c/12d6a5681a0a5cecc2af7860f0a1613fa7c6e947
- https://git.kernel.org/stable/c/1b175bc579f46520b11ecda443bcd2ee4904f66a
- https://git.kernel.org/stable/c/80ba43e9f799cbdd83842fc27db667289b3150f5
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-26934. Free for 1 server.
Get started free