Google: sys-kernel/lakitu-kernel-6_1: security update to 18244.151.50

high Tenable Cloud Security Plugin ID 450701

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: PCI/DPC: Fix use-after-free on
concurrent DPC and hot-removal Keith reports a use-after-free when a DPC event occurs concurrently to hot-
removal of the same portion of the hierarchy: The dpc_handler() awaits readiness of the secondary bus
below the Downstream Port where the DPC event occurred. To do so, it polls the config space of the first
child device on the secondary bus. If that child device is concurrently removed, accesses to its struct
pci_dev cause the kernel to oops. That's because pci_bridge_wait_for_secondary_bus() neglects to hold a
reference on the child device. Before v6.3, the function was only called on resume from system sleep or on
runtime resume. Holding a reference wasn't necessary back then because the pciehp IRQ thread could never
run concurrently. (On resume from system sleep, IRQs are not enabled until after the resume_noirq phase.
And runtime resume is always awaited before a PCI device is removed.) However starting with v6.3,
pci_bridge_wait_for_secondary_bus() is also called on a DPC event. Commit 53b54ad074de ("PCI/DPC: Await
readiness of secondary bus after reset"), which introduced that, failed to appreciate that
pci_bridge_wait_for_secondary_bus() now needs to hold a reference on the child device because
dpc_handler() and pciehp may indeed run concurrently. The commit was backported to v5.10+ stable kernels,
so that's the oldest one affected. Add the missing reference acquisition. Abridged stack trace: BUG:
unable to handle page fault for address: 00000000091400c0 CPU: 15 PID: 2464 Comm: irq/53-pcie-dpc 6.9.0
RIP: pci_bus_read_config_dword+0x17/0x50 pci_dev_wait() pci_bridge_wait_for_secondary_bus()
dpc_reset_link() pcie_do_recovery() dpc_handler() (CVE-2024-42302)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 18244.151.50 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 450701

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 97.35

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-42302

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2024-42302