{"id":"DEBIAN-CVE-2024-53207","details":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: MGMT: Fix possible deadlocks  This fixes possible deadlocks like the following caused by hci_cmd_sync_dequeue causing the destroy function to run:   INFO: task kworker/u19:0:143 blocked for more than 120 seconds.        Tainted: G        W  O        6.8.0-2024-03-19-intel-next-iLS-24ww14 #1  \"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message.  task:kworker/u19:0   state:D stack:0     pid:143   tgid:143   ppid:2      flags:0x00004000  Workqueue: hci0 hci_cmd_sync_work [bluetooth]  Call Trace:   \u003cTASK\u003e   __schedule+0x374/0xaf0   schedule+0x3c/0xf0   schedule_preempt_disabled+0x1c/0x30   __mutex_lock.constprop.0+0x3ef/0x7a0   __mutex_lock_slowpath+0x13/0x20   mutex_lock+0x3c/0x50   mgmt_set_connectable_complete+0xa4/0x150 [bluetooth]   ? kfree+0x211/0x2a0   hci_cmd_sync_dequeue+0xae/0x130 [bluetooth]   ? __pfx_cmd_complete_rsp+0x10/0x10 [bluetooth]   cmd_complete_rsp+0x26/0x80 [bluetooth]   mgmt_pending_foreach+0x4d/0x70 [bluetooth]   __mgmt_power_off+0x8d/0x180 [bluetooth]   ? _raw_spin_unlock_irq+0x23/0x40   hci_dev_close_sync+0x445/0x5b0 [bluetooth]   hci_set_powered_sync+0x149/0x250 [bluetooth]   set_powered_sync+0x24/0x60 [bluetooth]   hci_cmd_sync_work+0x90/0x150 [bluetooth]   process_one_work+0x13e/0x300   worker_thread+0x2f7/0x420   ? __pfx_worker_thread+0x10/0x10   kthread+0x107/0x140   ? __pfx_kthread+0x10/0x10   ret_from_fork+0x3d/0x60   ? __pfx_kthread+0x10/0x10   ret_from_fork_asm+0x1b/0x30   \u003c/TASK\u003e","modified":"2026-09-15T09:03:16.272287338Z","published":"2024-12-27T14:15:28.563Z","upstream":["CVE-2024-53207"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-53207"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.123-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-53207.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-53207.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-53207.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}