CVE-2024-57984 (GCVE-0-2024-57984)
Vulnerability from cvelistv5
Published
2025-02-27 02:07
Modified
2026-08-05 11:47
Summary
In the Linux kernel, the following vulnerability has been resolved: i3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition In dw_i3c_common_probe, &master->hj_work is bound with dw_i3c_hj_work. And dw_i3c_master_irq_handler can call dw_i3c_master_irq_handle_ibis function to start the work. If we remove the module which will call dw_i3c_common_remove to make cleanup, it will free master->base through i3c_master_unregister while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | dw_i3c_hj_work dw_i3c_common_remove | i3c_master_unregister(&master->base) | device_unregister(&master->dev) | device_release | //free master->base | | i3c_master_do_daa(&master->base) | //use master->base Fix it by ensuring that the work is canceled before proceeding with the cleanup in dw_i3c_common_remove.
Impacted products
Vendor Product Version
Linux Linux Version: 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef
Version: 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef
Version: 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef
Version: 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 7.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-57984",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-02-27T17:58:19.220421Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-416",
                "description": "CWE-416 Use After Free",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-02-27T18:02:28.323Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/i3c/master/dw-i3c-master.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "60d2fb033a999bb644f8e8606ff4a1b82de36c6f",
              "status": "affected",
              "version": "1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef",
              "versionType": "git"
            },
            {
              "lessThan": "9b0063098fcde17cd2894f2c96459b23388507ca",
              "status": "affected",
              "version": "1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef",
              "versionType": "git"
            },
            {
              "lessThan": "fc84dd3c909a372c0d130f5f84c404717c17eed8",
              "status": "affected",
              "version": "1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef",
              "versionType": "git"
            },
            {
              "lessThan": "b75439c945b94dd8a2b645355bdb56f948052601",
              "status": "affected",
              "version": "1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/i3c/master/dw-i3c-master.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.0"
            },
            {
              "lessThan": "5.0",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.76",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.13.*",
              "status": "unaffected",
              "version": "6.13.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.14",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.76",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.13",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13.2",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition\n\nIn dw_i3c_common_probe, \u0026master-\u003ehj_work is bound with\ndw_i3c_hj_work. And dw_i3c_master_irq_handler can call\ndw_i3c_master_irq_handle_ibis function to start the work.\n\nIf we remove the module which will call dw_i3c_common_remove to\nmake cleanup, it will free master-\u003ebase through i3c_master_unregister\nwhile the work mentioned above will be used. The sequence of operations\nthat may lead to a UAF bug is as follows:\n\nCPU0                                      CPU1\n\n                                     | dw_i3c_hj_work\ndw_i3c_common_remove                 |\ni3c_master_unregister(\u0026master-\u003ebase) |\ndevice_unregister(\u0026master-\u003edev)      |\ndevice_release                       |\n//free master-\u003ebase                  |\n                                     | i3c_master_do_daa(\u0026master-\u003ebase)\n                                     | //use master-\u003ebase\n\nFix it by ensuring that the work is canceled before proceeding with\nthe cleanup in dw_i3c_common_remove."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The attacker-controlled side of the race is driver teardown, reached locally via module unload or a write to the platform driver\u0027s sysfs unbind attribute, and the hot-join IBI side originates on the on-board I3C bus. No network or remote protocol path reaches this code, so the entry point is local system access.\nAC:L - The attacker directly controls the teardown side of the race and can repeat bind/unbind cycles indefinitely until the pending hj_work collides with i3c_master_unregister(), so success does not depend on conditions outside their influence. Hot-Join IBIs recur on any bus where hot-join is enabled, giving the attacker repeated windows.\nPR:L - A basic local account is sufficient to reach the i3c sysfs surface and drive the device teardown/re-probe cycling that opens the race window, and no capability check gates the vulnerable hj_work path itself. Consistent with the scoring of equivalent driver remove-path work-item UAFs, low privileges are the defensible assumption.\nUI:N - The attacker performs the removal and the Hot-Join IBI is delivered by hardware on the bus; no victim action, mount, or file open is required. Exploitation completes entirely from the attacker\u0027s own operations.\nS:U - The use-after-free corrupts kernel heap state within the same kernel security authority, with no crossing of a VM, IOMMU, or sandbox boundary. Impact is confined to the kernel that owns the vulnerable driver.\nC:H - The freed dw_i3c_master object is read back by i3c_master_do_daa(), including its ops pointer and device table, so an attacker who reclaims the allocation gains control over interpreted kernel memory and can leverage it for arbitrary kernel memory disclosure. Per use-after-free scoring guidance this is High.\nI:H - i3c_master_do_daa() calls master-\u003eops-\u003edo_daa(master) \u2014 an indirect branch through a function pointer read from freed memory \u2014 and i3c_master_register_new_i3c_devs() then mutates torn-down bus lists, providing both control-flow hijack and write primitives after heap spraying. This is full integrity compromise.\nA:H - Even without successful exploitation the work dereferences freed memory and performs readl/writel against MMIO already unmapped by devres, producing a kernel oops or panic. Any use-after-free of this kind is a reliable crash."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:47:10.554Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/60d2fb033a999bb644f8e8606ff4a1b82de36c6f"
        },
        {
          "url": "https://git.kernel.org/stable/c/9b0063098fcde17cd2894f2c96459b23388507ca"
        },
        {
          "url": "https://git.kernel.org/stable/c/fc84dd3c909a372c0d130f5f84c404717c17eed8"
        },
        {
          "url": "https://git.kernel.org/stable/c/b75439c945b94dd8a2b645355bdb56f948052601"
        }
      ],
      "title": "i3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-57984",
    "datePublished": "2025-02-27T02:07:09.373Z",
    "dateReserved": "2025-02-27T02:04:28.913Z",
    "dateUpdated": "2026-08-05T11:47:10.554Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 7.8, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"HIGH\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-57984\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-02-27T17:58:19.220421Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-416\", \"description\": \"CWE-416 Use After Free\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-02-27T17:58:20.920Z\"}}], \"cna\": {\"title\": \"i3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The attacker-controlled side of the race is driver teardown, reached locally via module unload or a write to the platform driver\u0027s sysfs unbind attribute, and the hot-join IBI side originates on the on-board I3C bus. No network or remote protocol path reaches this code, so the entry point is local system access.\\nAC:L - The attacker directly controls the teardown side of the race and can repeat bind/unbind cycles indefinitely until the pending hj_work collides with i3c_master_unregister(), so success does not depend on conditions outside their influence. Hot-Join IBIs recur on any bus where hot-join is enabled, giving the attacker repeated windows.\\nPR:L - A basic local account is sufficient to reach the i3c sysfs surface and drive the device teardown/re-probe cycling that opens the race window, and no capability check gates the vulnerable hj_work path itself. Consistent with the scoring of equivalent driver remove-path work-item UAFs, low privileges are the defensible assumption.\\nUI:N - The attacker performs the removal and the Hot-Join IBI is delivered by hardware on the bus; no victim action, mount, or file open is required. Exploitation completes entirely from the attacker\u0027s own operations.\\nS:U - The use-after-free corrupts kernel heap state within the same kernel security authority, with no crossing of a VM, IOMMU, or sandbox boundary. Impact is confined to the kernel that owns the vulnerable driver.\\nC:H - The freed dw_i3c_master object is read back by i3c_master_do_daa(), including its ops pointer and device table, so an attacker who reclaims the allocation gains control over interpreted kernel memory and can leverage it for arbitrary kernel memory disclosure. Per use-after-free scoring guidance this is High.\\nI:H - i3c_master_do_daa() calls master-\u003eops-\u003edo_daa(master) \\u2014 an indirect branch through a function pointer read from freed memory \\u2014 and i3c_master_register_new_i3c_devs() then mutates torn-down bus lists, providing both control-flow hijack and write primitives after heap spraying. This is full integrity compromise.\\nA:H - Even without successful exploitation the work dereferences freed memory and performs readl/writel against MMIO already unmapped by devres, producing a kernel oops or panic. Any use-after-free of this kind is a reliable crash.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef\", \"lessThan\": \"60d2fb033a999bb644f8e8606ff4a1b82de36c6f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef\", \"lessThan\": \"9b0063098fcde17cd2894f2c96459b23388507ca\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef\", \"lessThan\": \"fc84dd3c909a372c0d130f5f84c404717c17eed8\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef\", \"lessThan\": \"b75439c945b94dd8a2b645355bdb56f948052601\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/i3c/master/dw-i3c-master.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.0\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.0\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.6.76\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12.13\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.13.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.13.*\"}, {\"status\": \"unaffected\", \"version\": \"6.14\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/i3c/master/dw-i3c-master.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/60d2fb033a999bb644f8e8606ff4a1b82de36c6f\"}, {\"url\": \"https://git.kernel.org/stable/c/9b0063098fcde17cd2894f2c96459b23388507ca\"}, {\"url\": \"https://git.kernel.org/stable/c/fc84dd3c909a372c0d130f5f84c404717c17eed8\"}, {\"url\": \"https://git.kernel.org/stable/c/b75439c945b94dd8a2b645355bdb56f948052601\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ni3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition\\n\\nIn dw_i3c_common_probe, \u0026master-\u003ehj_work is bound with\\ndw_i3c_hj_work. And dw_i3c_master_irq_handler can call\\ndw_i3c_master_irq_handle_ibis function to start the work.\\n\\nIf we remove the module which will call dw_i3c_common_remove to\\nmake cleanup, it will free master-\u003ebase through i3c_master_unregister\\nwhile the work mentioned above will be used. The sequence of operations\\nthat may lead to a UAF bug is as follows:\\n\\nCPU0                                      CPU1\\n\\n                                     | dw_i3c_hj_work\\ndw_i3c_common_remove                 |\\ni3c_master_unregister(\u0026master-\u003ebase) |\\ndevice_unregister(\u0026master-\u003edev)      |\\ndevice_release                       |\\n//free master-\u003ebase                  |\\n                                     | i3c_master_do_daa(\u0026master-\u003ebase)\\n                                     | //use master-\u003ebase\\n\\nFix it by ensuring that the work is canceled before proceeding with\\nthe cleanup in dw_i3c_common_remove.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.76\", \"versionStartIncluding\": \"5.0\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.13\", \"versionStartIncluding\": \"5.0\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.13.2\", \"versionStartIncluding\": \"5.0\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.14\", \"versionStartIncluding\": \"5.0\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:47:10.554Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-57984\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:47:10.554Z\", \"dateReserved\": \"2025-02-27T02:04:28.913Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2025-02-27T02:07:09.373Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…