CVE-2024-58003
HIGHLinux Kernel 6.6-6.6.77, 6.7-6.12.13, 6.13-6.13.2 - Out-of-bounds Write via Extra fwnode_handle_put()
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: media: i2c: ds90ub9x3: Fix extra fwnode_handle_put() The ub913 and ub953 drivers call fwnode_handle_put(priv->sd.fwnode) as part of their remove process, and if the driver is removed multiple times, eventually leads to put "overflow", possibly causing memory corruption or crash. The fwnode_handle_put() is a leftover from commit 905f88ccebb1 ("media: i2c: ds90ub9x3: Fix sub-device matching"), which changed the code related to the sd.fwnode, but missed removing these fwnode_handle_put() calls.
References (4)
Core 4
Core References
Scores
CVSS v3
7.8
EPSS
0.0019
EPSS Percentile
8.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (14)
linux/Kernel
6.13.0 - 6.13.3linux
linux/Kernel
6.6.0 - 6.6.78linux
linux/Kernel
6.7.0 - 6.12.14linux
Linux/Linux
< 6.6
Linux/Linux
6.12.14 - 6.12.*
Linux/Linux
6.13.3 - 6.13.*
Linux/Linux
6.14
Linux/Linux
6.6
Linux/Linux
6.6.78 - 6.6.*
Linux/Linux
905f88ccebb14e42bcd19455b0d9c0d4808f1897 - 474d7baf91d37bc411fa60de5bbf03c9dd82e18a
... and 4 more
Published
Feb 27, 2025
Tracked Since
Feb 18, 2026