CVE-2024-58003

In the Linux kernel, the following vulnerability has been resolved: media: i2c: ds90ub9x3: Fix extra fwnode_handle_put() The ub913 and ub953 drivers call fwnode_handle_put(priv->sd.fwnode) as part of their remove process, and if the driver is removed multiple times, eventually leads to put "overflow", possibly causing memory corruption or crash. The fwnode_handle_put() is a leftover from commit 905f88ccebb1 ("media: i2c: ds90ub9x3: Fix sub-device matching"), which changed the code related to the sd.fwnode, but missed removing these fwnode_handle_put() calls.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Oct 2025, 13:04

Type Values Removed Values Added
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-787
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: media: i2c: ds90ub9x3: Fix extra fwnode_handle_put() Los controladores ub913 y ub953 llaman a fwnode_handle_put(priv->sd.fwnode) como parte de su proceso de eliminación y, si el controlador se elimina varias veces, eventualmente conduce a un "desbordamiento" de put, posiblemente causando corrupción de memoria o falla. fwnode_handle_put() es un remanente del commit 905f88ccebb1 ("media: i2c: ds90ub9x3: Fix sub-device matching"), que cambió el código relacionado con sd.fwnode, pero no eliminó estas llamadas fwnode_handle_put().
References () https://git.kernel.org/stable/c/474d7baf91d37bc411fa60de5bbf03c9dd82e18a - () https://git.kernel.org/stable/c/474d7baf91d37bc411fa60de5bbf03c9dd82e18a - Patch
References () https://git.kernel.org/stable/c/60b45ece41c5632a3a3274115a401cb244180646 - () https://git.kernel.org/stable/c/60b45ece41c5632a3a3274115a401cb244180646 - Patch
References () https://git.kernel.org/stable/c/70743d6a8b256225675711e7983825f1be86062d - () https://git.kernel.org/stable/c/70743d6a8b256225675711e7983825f1be86062d - Patch
References () https://git.kernel.org/stable/c/f4e4373322f8d4c19721831f7fb989e52d30dab0 - () https://git.kernel.org/stable/c/f4e4373322f8d4c19721831f7fb989e52d30dab0 - Patch

27 Feb 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-27 03:15

Updated : 2025-10-23 13:04


NVD link : CVE-2024-58003

Mitre link : CVE-2024-58003

CVE.ORG link : CVE-2024-58003


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-787

Out-of-bounds Write