CVE-2024-49986 (GCVE-0-2024-49986)
Vulnerability from cvelistv5
Published
2024-10-21 18:02
Modified
2026-08-05 11:40
Summary
In the Linux kernel, the following vulnerability has been resolved: platform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors x86_android_tablet_remove() frees the pdevs[] array, so it should not be used after calling x86_android_tablet_remove(). When platform_device_register() fails, store the pdevs[x] PTR_ERR() value into the local ret variable before calling x86_android_tablet_remove() to avoid using pdevs[] after it has been freed.
Impacted products
Vendor Product Version
Linux Linux Version: 5eba0141206ea521bbcfcf5067c174e825e943dd
Version: 5eba0141206ea521bbcfcf5067c174e825e943dd
Version: 5eba0141206ea521bbcfcf5067c174e825e943dd
Version: 5eba0141206ea521bbcfcf5067c174e825e943dd
Version: 5eba0141206ea521bbcfcf5067c174e825e943dd
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-49986",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-22T13:31:52.405386Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-22T13:38:43.597Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:24:08.353Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/platform/x86/x86-android-tablets/core.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "ba0b09a2f327319e252d8f3032019b958c0a5cd9",
              "status": "affected",
              "version": "5eba0141206ea521bbcfcf5067c174e825e943dd",
              "versionType": "git"
            },
            {
              "lessThan": "aac871e493fc8809e60209d9899b1af07e9dbfc8",
              "status": "affected",
              "version": "5eba0141206ea521bbcfcf5067c174e825e943dd",
              "versionType": "git"
            },
            {
              "lessThan": "f08adc5177bd4343df09033f62ab562c09ba7f7d",
              "status": "affected",
              "version": "5eba0141206ea521bbcfcf5067c174e825e943dd",
              "versionType": "git"
            },
            {
              "lessThan": "73a98cf79e4dbfa3d0c363e826c65aae089b313c",
              "status": "affected",
              "version": "5eba0141206ea521bbcfcf5067c174e825e943dd",
              "versionType": "git"
            },
            {
              "lessThan": "2fae3129c0c08e72b1fe93e61fd8fd203252094a",
              "status": "affected",
              "version": "5eba0141206ea521bbcfcf5067c174e825e943dd",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/platform/x86/x86-android-tablets/core.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.17"
            },
            {
              "lessThan": "5.17",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.118",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.55",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.14",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.118",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.55",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.14",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.3",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "5.17",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors\n\nx86_android_tablet_remove() frees the pdevs[] array, so it should not\nbe used after calling x86_android_tablet_remove().\n\nWhen platform_device_register() fails, store the pdevs[x] PTR_ERR() value\ninto the local ret variable before calling x86_android_tablet_remove()\nto avoid using pdevs[] after it has been freed."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is a platform driver `__init` probe routine reached only from `module_init()` on the local machine (boot-time DMI-modalias autoload or an explicit modprobe); there is no network, adjacent-network, or physical-interface path to it.\nAC:L - The defect fires unconditionally whenever `platform_device_register_full()` returns an error on affected hardware, and an attacker able to load/reload the module can retry the probe under heavy memory pressure or fault injection until an allocation in the registration path fails; no race needs to be won and no memory layout must be guessed.\nPR:L - On the affected tablets the module is autoloaded at boot via its DMI modalias, so the vulnerable path executes without the attacker holding any elevated capability, and the resulting dangling globals affect every local user of the system.\nUI:N - The probe path runs automatically during module init/boot; no victim has to open a file, mount a filesystem, or take any other action for the use-after-free to occur.\nS:U - The freed-memory access and the resulting double-free are confined to kernel slab memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a use-after-free read of freed slab memory whose contents an attacker can influence via heap grooming, and the false-success cascade leaves five dangling global pointers that are later dereferenced, giving a path to disclosing arbitrary reclaimed kernel data.\nI:H - When the freed slot reads back as zero the probe falsely reports success, so `x86_android_tablet_remove()` runs a second time and double-frees five allocations while unregistering devices from freed arrays \u2014 a double-free/UAF-write primitive that is the classic basis for slab corruption and control-flow hijack.\nA:H - The use-after-free read produces a KASAN report (a panic with `kasan.fault=panic`/`panic_on_warn`), and the downstream double-free and unregistration of stale device pointers reliably oops or panics the kernel."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:40:54.750Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ba0b09a2f327319e252d8f3032019b958c0a5cd9"
        },
        {
          "url": "https://git.kernel.org/stable/c/aac871e493fc8809e60209d9899b1af07e9dbfc8"
        },
        {
          "url": "https://git.kernel.org/stable/c/f08adc5177bd4343df09033f62ab562c09ba7f7d"
        },
        {
          "url": "https://git.kernel.org/stable/c/73a98cf79e4dbfa3d0c363e826c65aae089b313c"
        },
        {
          "url": "https://git.kernel.org/stable/c/2fae3129c0c08e72b1fe93e61fd8fd203252094a"
        }
      ],
      "title": "platform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-49986",
    "datePublished": "2024-10-21T18:02:30.507Z",
    "dateReserved": "2024-10-21T12:17:06.054Z",
    "dateUpdated": "2026-08-05T11:40:54.750Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T22:24:08.353Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-49986\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-10-22T13:31:52.405386Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-10-22T13:31:55.514Z\"}}], \"cna\": {\"title\": \"platform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerable code is a platform driver `__init` probe routine reached only from `module_init()` on the local machine (boot-time DMI-modalias autoload or an explicit modprobe); there is no network, adjacent-network, or physical-interface path to it.\\nAC:L - The defect fires unconditionally whenever `platform_device_register_full()` returns an error on affected hardware, and an attacker able to load/reload the module can retry the probe under heavy memory pressure or fault injection until an allocation in the registration path fails; no race needs to be won and no memory layout must be guessed.\\nPR:L - On the affected tablets the module is autoloaded at boot via its DMI modalias, so the vulnerable path executes without the attacker holding any elevated capability, and the resulting dangling globals affect every local user of the system.\\nUI:N - The probe path runs automatically during module init/boot; no victim has to open a file, mount a filesystem, or take any other action for the use-after-free to occur.\\nS:U - The freed-memory access and the resulting double-free are confined to kernel slab memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\\nC:H - This is a use-after-free read of freed slab memory whose contents an attacker can influence via heap grooming, and the false-success cascade leaves five dangling global pointers that are later dereferenced, giving a path to disclosing arbitrary reclaimed kernel data.\\nI:H - When the freed slot reads back as zero the probe falsely reports success, so `x86_android_tablet_remove()` runs a second time and double-frees five allocations while unregistering devices from freed arrays \\u2014 a double-free/UAF-write primitive that is the classic basis for slab corruption and control-flow hijack.\\nA:H - The use-after-free read produces a KASAN report (a panic with `kasan.fault=panic`/`panic_on_warn`), and the downstream double-free and unregistration of stale device pointers reliably oops or panics the kernel.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5eba0141206ea521bbcfcf5067c174e825e943dd\", \"lessThan\": \"ba0b09a2f327319e252d8f3032019b958c0a5cd9\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5eba0141206ea521bbcfcf5067c174e825e943dd\", \"lessThan\": \"aac871e493fc8809e60209d9899b1af07e9dbfc8\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5eba0141206ea521bbcfcf5067c174e825e943dd\", \"lessThan\": \"f08adc5177bd4343df09033f62ab562c09ba7f7d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5eba0141206ea521bbcfcf5067c174e825e943dd\", \"lessThan\": \"73a98cf79e4dbfa3d0c363e826c65aae089b313c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5eba0141206ea521bbcfcf5067c174e825e943dd\", \"lessThan\": \"2fae3129c0c08e72b1fe93e61fd8fd203252094a\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/platform/x86/x86-android-tablets/core.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.17\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.17\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.1.118\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.55\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10.14\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/platform/x86/x86-android-tablets/core.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/ba0b09a2f327319e252d8f3032019b958c0a5cd9\"}, {\"url\": \"https://git.kernel.org/stable/c/aac871e493fc8809e60209d9899b1af07e9dbfc8\"}, {\"url\": \"https://git.kernel.org/stable/c/f08adc5177bd4343df09033f62ab562c09ba7f7d\"}, {\"url\": \"https://git.kernel.org/stable/c/73a98cf79e4dbfa3d0c363e826c65aae089b313c\"}, {\"url\": \"https://git.kernel.org/stable/c/2fae3129c0c08e72b1fe93e61fd8fd203252094a\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nplatform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors\\n\\nx86_android_tablet_remove() frees the pdevs[] array, so it should not\\nbe used after calling x86_android_tablet_remove().\\n\\nWhen platform_device_register() fails, store the pdevs[x] PTR_ERR() value\\ninto the local ret variable before calling x86_android_tablet_remove()\\nto avoid using pdevs[] after it has been freed.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.118\", \"versionStartIncluding\": \"5.17\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.55\", \"versionStartIncluding\": \"5.17\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.14\", \"versionStartIncluding\": \"5.17\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.3\", \"versionStartIncluding\": \"5.17\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"5.17\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:40:54.750Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-49986\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:40:54.750Z\", \"dateReserved\": \"2024-10-21T12:17:06.054Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-10-21T18:02:30.507Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…