Google: sys-kernel/lakitu-kernel-6_1: security update to 18244.151.9

medium Tenable Self-Hosted Container Security Plugin ID 451678

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: remove lock of otg
mode during gadget suspend/resume to avoid deadlock When config CONFIG_USB_DWC3_DUAL_ROLE is selected, and
trigger system to enter suspend status with below command: echo mem > /sys/power/state There will be a
deadlock issue occurring. Detailed invoking path as below: dwc3_suspend_common()
spin_lock_irqsave(&dwc->lock, flags); <-- 1st dwc3_gadget_suspend(dwc); dwc3_gadget_soft_disconnect(dwc);
spin_lock_irqsave(&dwc->lock, flags); <-- 2nd This issue is exposed by commit c7ebd8149ee5 ("usb: dwc3:
gadget: Fix NULL pointer dereference in dwc3_gadget_suspend") that removes the code of checking whether
dwc->gadget_driver is NULL or not. It causes the following code is executed and deadlock occurs when
trying to get the spinlock. In fact, the root cause is the commit 5265397f9442("usb: dwc3: Remove DWC3
locking during gadget suspend/resume") that forgot to remove the lock of otg mode. So, remove the
redundant lock of otg mode during gadget suspend/resume. (CVE-2024-42085)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 18244.151.9 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451678

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-42085

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/17/2024

Reference Information

CVE: CVE-2024-42085