CVE-2024-40976
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-40976 affects the Linux kernel's DRM (Direct Rendering Manager) Lima driver. The vulnerability was discovered in July 2024 and involves a race condition in the rendering job timeout handling mechanism (NVD).

Technical details

The vulnerability stems from a race condition where a rendering job might take just long enough to trigger the DRM scheduler job timeout handler but still complete before the hard reset is executed by the timeout handler. This unexpected scenario can result in race conditions not anticipated by the timeout handler. In specific cases, it may lead to a reference count imbalance in lima_pm_idle, manifesting as a stack dump in the system logs (Kernel Commit).

Impact

When exploited, this vulnerability can cause a reference count imbalance in the Lima driver's power management system, potentially leading to system instability or crashes. The issue specifically affects systems using the Lima GPU driver in the Linux kernel (NVD).

Exploitability

The vulnerability requires local access to a system running the affected Linux kernel version with the Lima GPU driver. There are no known reports of this vulnerability being exploited in the wild (NVD).

Mitigation and workarounds

The issue has been fixed by masking interrupts at the beginning of the timeout handler, effectively preventing the race condition. The fix involves adding code to mask IRQs before performing the hard reset, with IRQs being re-enabled during the subsequent hard reset recovery process. This patch has been integrated into various Linux kernel versions (Kernel Commit). The fix is available in Linux kernel packages linux-6.1 version 6.1.119-1~deb11u1 for Debian 11 (Debian LTS).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68454HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-hwe-7.0
NoYesAug 13, 2026
CVE-2026-68452HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-raspi-5.4
NoYesAug 13, 2026
CVE-2026-68451HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-nvidia
NoYesAug 13, 2026
CVE-2026-68453HIGH7.1
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-core
NoYesAug 13, 2026
CVE-2026-68450NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-aws
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management