VYPR
High severity7.8NVD Advisory· Published Jun 24, 2024· Updated Aug 4, 2026

CVE-2024-39292

CVE-2024-39292

Description

In the Linux kernel, the following vulnerability has been resolved:

um: Add winch to winch_handlers before registering winch IRQ

Registering a winch IRQ is racy, an interrupt may occur before the winch is added to the winch_handlers list.

If that happens, register_winch_irq() adds to that list a winch that is scheduled to be (or has already been) freed, causing a panic later in winch_cleanup().

Avoid the race by adding the winch to the winch_handlers list before registering the IRQ, and rolling back if um_request_irq() fails.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Linux/Kernel4 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <2.6.23
    • cpe:2.3:o:linux:linux_kernel:6.10.0:rc1:*:*:*:*:*:*
    • (no CPE)range: 2.6.23
    • (no CPE)
  • osv-coords
    Range: >= 2.6.23, < 4.19.316

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.