Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-49963

5.5 · MEDIUM
Published Oct 21, 2024 linux EPSS 0.26% (17th pctl)

Overview

CVE-2024-49963 is a medium-severity vulnerability affecting linux linux_kernel. It was published on October 21, 2024 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

mailbox: bcm2835: Fix timeout during suspend mode

During noirq suspend phase the Raspberry Pi power driver suffer of

firmware property timeouts. The reason is that the IRQ of the underlying

BCM2835 mailbox is disabled and rpi_firmware_property_list() will always

run into a timeout [1].

Since the VideoCore side isn't consider as a wakeup source, set the

IRQF_NO_SUSPEND flag for the mailbox IRQ in order to keep it enabled

during suspend-resume cycle.

[1]

PM: late suspend of devices complete after 1.754 msecs

WARNING: CPU: 0 PID: 438 at drivers/firmware/raspberrypi.c:128

rpi_firmware_property_list+0x204/0x22c

Firmware transaction 0x00028001 timeout

Modules linked in:

CPU: 0 PID: 438 Comm: bash Tainted: G C 6.9.3-dirty #17

Hardware name: BCM2835

Call trace:

unwind_backtrace from show_stack+0x18/0x1c

show_stack from dump_stack_lvl+0x34/0x44

dump_stack_lvl from __warn+0x88/0xec

__warn from warn_slowpath_

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 4.2, < 5.10.227 Affected

Frequently Asked Questions

What is CVE-2024-49963?

CVE-2024-49963 is a medium-severity vulnerability affecting linux linux_kernel. It was published on October 21, 2024 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2024-49963?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2024-49963?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-49963?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-49963 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.