CVE-2024-58003

HIGH

Linux Kernel 6.6-6.6.77, 6.7-6.12.13, 6.13-6.13.2 - Out-of-bounds Write via Extra fwnode_handle_put()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: media: i2c: ds90ub9x3: Fix extra fwnode_handle_put() The ub913 and ub953 drivers call fwnode_handle_put(priv->sd.fwnode) as part of their remove process, and if the driver is removed multiple times, eventually leads to put "overflow", possibly causing memory corruption or crash. The fwnode_handle_put() is a leftover from commit 905f88ccebb1 ("media: i2c: ds90ub9x3: Fix sub-device matching"), which changed the code related to the sd.fwnode, but missed removing these fwnode_handle_put() calls.

Scores

CVSS v3 7.8
EPSS 0.0019
EPSS Percentile 8.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (14)
linux/Kernel 6.13.0 - 6.13.3linux
linux/Kernel 6.6.0 - 6.6.78linux
linux/Kernel 6.7.0 - 6.12.14linux
Linux/Linux < 6.6
Linux/Linux 6.12.14 - 6.12.*
Linux/Linux 6.13.3 - 6.13.*
Linux/Linux 6.14
Linux/Linux 6.6
Linux/Linux 6.6.78 - 6.6.*
Linux/Linux 905f88ccebb14e42bcd19455b0d9c0d4808f1897 - 474d7baf91d37bc411fa60de5bbf03c9dd82e18a
... and 4 more
Published Feb 27, 2025
Tracked Since Feb 18, 2026