Bottlerocket: bottlerocket-kernel-5.10, kernel-5.10: security update to 5.10.230bottlerocket-kernel-5.15, kernel-5.15: security update to 5.15.173

medium Tenable Cloud Security Plugin ID 428106

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: io_uring: fix possible deadlock in
io_register_iowq_max_workers() The io_register_iowq_max_workers() function calls io_put_sq_data(), which
acquires the sqd->lock without releasing the uring_lock. Similar to the commit 009ad9f0c6ee ("io_uring:
drop ctx->uring_lock before acquiring sqd->lock"), this can lead to a potential deadlock situation. To
resolve this issue, the uring_lock is released before calling io_put_sq_data(), and then it is re-acquired
after the function call. This change ensures that the locks are acquired in the correct order, preventing
the possibility of a deadlock. (CVE-2024-41080)

Plugin Details

Severity: Medium

ID: 428106

Version: Revision 1.5

Type: Local

Published: 6/30/2025

Updated: 6/8/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-41080

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/29/2024

Reference Information

CVE: CVE-2024-41080