{"id":"DEBIAN-CVE-2024-50266","details":"In the Linux kernel, the following vulnerability has been resolved:  clk: qcom: videocc-sm8350: use HW_CTRL_TRIGGER for vcodec GDSCs  A recent change in the venus driver results in a stuck clock on the Lenovo ThinkPad X13s, for example, when streaming video in firefox:  \tvideo_cc_mvs0_clk status stuck at 'off' \tWARNING: CPU: 6 PID: 2885 at drivers/clk/qcom/clk-branch.c:87 clk_branch_wait+0x144/0x15c \t... \tCall trace: \t clk_branch_wait+0x144/0x15c \t clk_branch2_enable+0x30/0x40 \t clk_core_enable+0xd8/0x29c \t clk_enable+0x2c/0x4c \t vcodec_clks_enable.isra.0+0x94/0xd8 [venus_core] \t coreid_power_v4+0x464/0x628 [venus_core] \t vdec_start_streaming+0xc4/0x510 [venus_dec] \t vb2_start_streaming+0x6c/0x180 [videobuf2_common] \t vb2_core_streamon+0x120/0x1dc [videobuf2_common] \t vb2_streamon+0x1c/0x6c [videobuf2_v4l2] \t v4l2_m2m_ioctl_streamon+0x30/0x80 [v4l2_mem2mem] \t v4l_streamon+0x24/0x30 [videodev]  using the out-of-tree sm8350/sc8280xp venus support. [1]  Update also the sm8350/sc8280xp GDSC definitions so that the hw control mode can be changed at runtime as the venus driver now requires.","modified":"2026-09-15T09:03:10.825104665Z","published":"2024-11-19T02:16:28.540Z","upstream":["CVE-2024-50266"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-50266"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50266.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50266.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}