{
  "schema_version": "1.6.1",
  "id": "RPI-CVE-2024-36944",
  "modified": "2026-10-07T17:22:01Z",
  "upstream": [
    "CVE-2024-36944"
  ],
  "published": "2024-05-30T15:36:11Z",
  "summary": "Reapply \"drm/qxl: simplify qxl_fence_wait\"",
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nReapply \"drm/qxl: simplify qxl_fence_wait\"\n\nThis reverts commit 07ed11afb68d94eadd4ffc082b97c2331307c5ea.\n\nStephen Rostedt reports:\n \"I went to run my tests on my VMs and the tests hung on boot up.\n  Unfortunately, the most I ever got out was:\n\n  [   93.607888] Testing event system initcall: OK\n  [   93.667730] Running tests on all trace events:\n  [   93.669757] Testing all events: OK\n  [   95.631064] ------------[ cut here ]------------\n  Timed out after 60 seconds\"\n\nand further debugging points to a possible circular locking dependency\nbetween the console_owner locking and the worker pool locking.\n\nReverting the commit allows Steve's VM to boot to completion again.\n\n[ This may obviously result in the \"[TTM] Buffer eviction failed\"\n  messages again, which was the reason for that original revert. But at\n  this point this seems preferable to a non-booting system... ]",
  "affected": [
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:12",
        "name": "linux"
      },
      "versions": [
        "1:6.6.28-1+rpt1"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.6.28+rpt-rpi-2712",
            "binary_version": "1:6.6.28-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.28+rpt-rpi-v6",
            "binary_version": "1:6.6.28-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.28+rpt-rpi-v7",
            "binary_version": "1:6.6.28-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.28+rpt-rpi-v7l",
            "binary_version": "1:6.6.28-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.28+rpt-rpi-v8",
            "binary_version": "1:6.6.28-1+rpt1"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.6.28-1+rpt1": {
            "linux_commit": "0c341f47adc3578cd5f817aa20ee2b7f9ae6b23e",
            "upstream_version": "6.6.28",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.31"
          }
        }
      }
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-36944"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/4a89ac4b0921c4ea21eb1b4cf3a469a91bacfcea"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/b548c53bc3ab83dc6fc86c8e840f013b2032267a"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/148ed8b4d64f94ab079c8f0d88c3f444db97ba97"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/3dfe35d8683daf9ba69278643efbabe40000bbf6"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/3628e0383dd349f02f882e612ab6184e4bb3dc10"
    }
  ],
  "database_specific": {
    "source": "https://git.kernel.org/pub/scm/linux/security/vulns.git",
    "upstream_modified": "2026-05-12T04:54:46Z"
  }
}
