Junglewise Threat Intelligence

CVE-2024-35997: Linux Kernel lock-up in HID i2c-hid driver

CVE-2024-35997 · Severity: medium · CVSS 5.5 · Published 2024-05-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's I2C HID driver can cause a system lock-up or denial of service. This driver is responsible for managing input devices like touchpads or keyboards that connect via the I2C bus. An exploit could allow a local user to trigger an infinite loop in the system's interrupt handler, effectively freezing the computer and requiring a hard reboot.

Technical details

A vulnerability exists in the i2c-hid driver of the Linux kernel where the I2C_HID_READ_PENDING flag, used to serialize I2C operations, can cause a deadlock. If this flag is set during a transfer (i2c_hid_xfer) and an interrupt occurs, the interrupt handler (i2c_hid_irq) checks the flag and returns immediately without clearing the interrupt source. Because the interrupt handler is a real-time (RT) task, it re-triggers in an infinite loop, preventing the original task from clearing the flag and resulting in a CPU lock-up. The fix involves removing the redundant I2C_HID_READ_PENDING flag, as the I2C core already provides sufficient locking. Patches have been backported to multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 3.8 to 4.19.313, 4.20 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.158, 5.16 to 6.1.90, 6.2 to 6.6.30, 6.7 to 6.8.9

Timeline

  • 2024-03-18: other: Initial patch authored
  • 2024-05-02: patched: Patch committed to stable trees
  • 2024-05-20: disclosed: CVE published

References

Related threats