{"id":"DEBIAN-CVE-2024-26806","details":"In the Linux kernel, the following vulnerability has been resolved:  spi: cadence-qspi: remove system-wide suspend helper calls from runtime PM hooks  The -\u003eruntime_suspend() and -\u003eruntime_resume() callbacks are not expected to call spi_controller_suspend() and spi_controller_resume(). Remove calls to those in the cadence-qspi driver.  Those helpers have two roles currently:  - They stop/start the queue, including dealing with the kworker.  - They toggle the SPI controller SPI_CONTROLLER_SUSPENDED flag. It    requires acquiring ctlr-\u003ebus_lock_mutex.  Step one is irrelevant because cadence-qspi is not queued. Step two however has two implications:  - A deadlock occurs, because -\u003eruntime_resume() is called in a context    where the lock is already taken (in the -\u003eexec_op() callback, where    the usage count is incremented).  - It would disallow all operations once the device is auto-suspended.  Here is a brief call tree highlighting the mutex deadlock:  spi_mem_exec_op()         ...         spi_mem_access_start()                 mutex_lock(&ctlr-\u003ebus_lock_mutex)          cqspi_exec_mem_op()                 pm_runtime_resume_and_get()                         cqspi_resume()                                 spi_controller_resume()                                         mutex_lock(&ctlr-\u003ebus_lock_mutex)                 ...          spi_mem_access_end()                 mutex_unlock(&ctlr-\u003ebus_lock_mutex)         ...","modified":"2026-09-15T09:03:00.203943874Z","published":"2024-04-04T09:15:09.333Z","upstream":["CVE-2024-26806"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-26806"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26806.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26806.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}