
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-26714 affects the Linux kernel's interconnect subsystem, specifically the Qualcomm SC8180x driver. The vulnerability was discovered and disclosed in April 2024, relating to a hardware connection issue where the CO0 BCM (Bus Clock Manager) component needs to maintain constant operation to prevent system hangs (Kernel Git).
The vulnerability exists in the interconnect/qcom/sc8180x.c driver where the CO0 BCM was not properly marked as keepalive. When the BCM is not kept active, it causes the UFS controller to lose its connection to the rest of the SoC (System on Chip), resulting in platform hangs and extensive system log messages (Kernel Git).
When exploited, this vulnerability can cause the platform to hang and generate excessive log messages. The issue specifically affects the UFS controller's connectivity to the SoC, potentially disrupting storage operations and system stability (Kernel Git).
The vulnerability requires no special privileges to trigger, as it's a design issue in the hardware interconnect management. The issue manifests when the CO0 BCM is allowed to become inactive, which can occur during normal system operation (Kernel Git).
The issue has been fixed by marking the CO0 BCM as keepalive in the driver code. The fix was implemented through a patch that adds the keepalive flag to the bcm_co0 structure. This ensures the BCM remains active at all times, preventing the connection loss and subsequent system hangs (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."