{"id":"DEBIAN-CVE-2024-26877","details":"In the Linux kernel, the following vulnerability has been resolved:  crypto: xilinx - call finalize with bh disabled  When calling crypto_finalize_request, BH should be disabled to avoid triggering the following calltrace:      ------------[ cut here ]------------     WARNING: CPU: 2 PID: 74 at crypto/crypto_engine.c:58 crypto_finalize_request+0xa0/0x118     Modules linked in: cryptodev(O)     CPU: 2 PID: 74 Comm: firmware:zynqmp Tainted: G           O       6.8.0-rc1-yocto-standard #323     Hardware name: ZynqMP ZCU102 Rev1.0 (DT)     pstate: 40000005 (nZcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)     pc : crypto_finalize_request+0xa0/0x118     lr : crypto_finalize_request+0x104/0x118     sp : ffffffc085353ce0     x29: ffffffc085353ce0 x28: 0000000000000000 x27: ffffff8808ea8688     x26: ffffffc081715038 x25: 0000000000000000 x24: ffffff880100db00     x23: ffffff880100da80 x22: 0000000000000000 x21: 0000000000000000     x20: ffffff8805b14000 x19: ffffff880100da80 x18: 0000000000010450     x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000     x14: 0000000000000003 x13: 0000000000000000 x12: ffffff880100dad0     x11: 0000000000000000 x10: ffffffc0832dcd08 x9 : ffffffc0812416d8     x8 : 00000000000001f4 x7 : ffffffc0830d2830 x6 : 0000000000000001     x5 : ffffffc082091000 x4 : ffffffc082091658 x3 : 0000000000000000     x2 : ffffffc7f9653000 x1 : 0000000000000000 x0 : ffffff8802d20000     Call trace:      crypto_finalize_request+0xa0/0x118      crypto_finalize_aead_request+0x18/0x30      zynqmp_handle_aes_req+0xcc/0x388      crypto_pump_work+0x168/0x2d8      kthread_worker_fn+0xfc/0x3a0      kthread+0x118/0x138      ret_from_fork+0x10/0x20     irq event stamp: 40     hardirqs last  enabled at (39): [\u003cffffffc0812416f8\u003e] _raw_spin_unlock_irqrestore+0x70/0xb0     hardirqs last disabled at (40): [\u003cffffffc08122d208\u003e] el1_dbg+0x28/0x90     softirqs last  enabled at (36): [\u003cffffffc080017dec\u003e] kernel_neon_begin+0x8c/0xf0     softirqs last disabled at (34): [\u003cffffffc080017dc0\u003e] kernel_neon_begin+0x60/0xf0     ---[ end trace 0000000000000000 ]---","modified":"2026-09-15T09:02:55.977497572Z","published":"2024-04-17T11:15:09.820Z","upstream":["CVE-2024-26877"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-26877"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.85-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26877.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26877.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26877.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}