Vulnerability Description
An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fepriv,events). In dvb_frontend_test_event, down(&fepriv->sem) is called. However, wait_event_interruptible would put the process to sleep, and down(&fepriv->sem) may block the process.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 6.2 |
| Fedoraproject | Fedora | 37 |
| Debian | Debian Linux | 10.0 |
| Netapp | H410C Firmware | - |
| Netapp | H410C | - |
Related Weaknesses (CWE)
References
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b8c75
- https://lists.debian.org/debian-lts-announce/2023/07/msg00030.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lore.kernel.org/all/CA+UBctCu7fXn4q41O_3=id1+OdyQ85tZY1x+TkT-6OVBL6KAUw%
- https://security.netapp.com/advisory/ntap-20230929-0003/Third Party Advisory
- https://www.debian.org/security/2023/dsa-5448Third Party Advisory
- https://www.debian.org/security/2023/dsa-5480Third Party Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b8c75
- https://lists.debian.org/debian-lts-announce/2023/07/msg00030.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lore.kernel.org/all/CA+UBctCu7fXn4q41O_3=id1+OdyQ85tZY1x+TkT-6OVBL6KAUw%
FAQ
What is CVE-2023-31084?
CVE-2023-31084 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interrupt...
How severe is CVE-2023-31084?
CVE-2023-31084 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31084?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora, Debian Debian Linux, Netapp H410C Firmware, Netapp H410C.