CVE-2024-50166

MEDIUM

Linux Kernel 4.5-6.6.58, 6.7.0-6.11.5 - Reference Count Leak in FSL/FMAN Device Binding

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: fsl/fman: Fix refcount handling of fman-related devices In mac_probe() there are multiple calls to of_find_device_by_node(), fman_bind() and fman_port_bind() which takes references to of_dev->dev. Not all references taken by these calls are released later on error path in mac_probe() and in mac_remove() which lead to reference leaks. Add references release.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (12)
linux/Kernel 4.5.0 - 6.6.59linux
linux/Kernel 6.7.0 - 6.11.6linux
Linux/Linux < 4.5
Linux/Linux 3933961682a30ae7d405cda344c040a129fea422 - 1dec67e0d9fbb087c2ab17bf1bd17208231c3bb1
Linux/Linux 3933961682a30ae7d405cda344c040a129fea422 - 3c2a3619d565fe16bf59b0a047bab103a2ee4490
Linux/Linux 3933961682a30ae7d405cda344c040a129fea422 - 5ed4334fc9512f934fe2ae9c4cf7f8142e451b8b
Linux/Linux 4.5
Linux/Linux 6.11.6 - 6.11.*
Linux/Linux 6.12
Linux/Linux 6.6.59 - 6.6.*
... and 2 more
Published Nov 07, 2024
Tracked Since Feb 18, 2026