{"id":"DEBIAN-CVE-2024-26775","details":"In the Linux kernel, the following vulnerability has been resolved:  aoe: avoid potential deadlock at set_capacity  Move set_capacity() outside of the section procected by (&d-\u003elock). To avoid possible interrupt unsafe locking scenario:          CPU0                    CPU1         ----                    ---- [1] lock(&bdev-\u003ebd_size_lock);                                 local_irq_disable();                             [2] lock(&d-\u003elock);                             [3] lock(&bdev-\u003ebd_size_lock);    \u003cInterrupt\u003e [4]  lock(&d-\u003elock);    *** DEADLOCK ***  Where [1](&bdev-\u003ebd_size_lock) hold by zram_add()-\u003eset_capacity(). [2]lock(&d-\u003elock) hold by aoeblk_gdalloc(). And aoeblk_gdalloc() is trying to acquire [3](&bdev-\u003ebd_size_lock) at set_capacity() call. In this situation an attempt to acquire [4]lock(&d-\u003elock) from aoecmd_cfg_rsp() will lead to deadlock.  So the simplest solution is breaking lock dependency [2](&d-\u003elock) -\u003e [3](&bdev-\u003ebd_size_lock) by moving set_capacity() outside.","modified":"2026-09-15T09:03:05.403738255Z","published":"2024-04-03T17:15:53.187Z","upstream":["CVE-2024-26775"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-26775"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.82-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26775.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26775.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26775.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}