CVE-2024-58003 (GCVE-0-2024-58003)
Vulnerability from cvelistv5
Published
2025-02-27 02:12
Modified
2026-08-05 11:47
Summary
In the Linux kernel, the following vulnerability has been resolved: media: i2c: ds90ub9x3: Fix extra fwnode_handle_put() The ub913 and ub953 drivers call fwnode_handle_put(priv->sd.fwnode) as part of their remove process, and if the driver is removed multiple times, eventually leads to put "overflow", possibly causing memory corruption or crash. The fwnode_handle_put() is a leftover from commit 905f88ccebb1 ("media: i2c: ds90ub9x3: Fix sub-device matching"), which changed the code related to the sd.fwnode, but missed removing these fwnode_handle_put() calls.
Impacted products
Vendor Product Version
Linux Linux Version: 905f88ccebb14e42bcd19455b0d9c0d4808f1897
Version: 905f88ccebb14e42bcd19455b0d9c0d4808f1897
Version: 905f88ccebb14e42bcd19455b0d9c0d4808f1897
Version: 905f88ccebb14e42bcd19455b0d9c0d4808f1897
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/media/i2c/ds90ub913.c",
            "drivers/media/i2c/ds90ub953.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "474d7baf91d37bc411fa60de5bbf03c9dd82e18a",
              "status": "affected",
              "version": "905f88ccebb14e42bcd19455b0d9c0d4808f1897",
              "versionType": "git"
            },
            {
              "lessThan": "f4e4373322f8d4c19721831f7fb989e52d30dab0",
              "status": "affected",
              "version": "905f88ccebb14e42bcd19455b0d9c0d4808f1897",
              "versionType": "git"
            },
            {
              "lessThan": "70743d6a8b256225675711e7983825f1be86062d",
              "status": "affected",
              "version": "905f88ccebb14e42bcd19455b0d9c0d4808f1897",
              "versionType": "git"
            },
            {
              "lessThan": "60b45ece41c5632a3a3274115a401cb244180646",
              "status": "affected",
              "version": "905f88ccebb14e42bcd19455b0d9c0d4808f1897",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/media/i2c/ds90ub913.c",
            "drivers/media/i2c/ds90ub953.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "lessThan": "6.6",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.78",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.14",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.13.*",
              "status": "unaffected",
              "version": "6.13.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.14",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.78",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.14",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13.3",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: i2c: ds90ub9x3: Fix extra fwnode_handle_put()\n\nThe ub913 and ub953 drivers call fwnode_handle_put(priv-\u003esd.fwnode) as\npart of their remove process, and if the driver is removed multiple\ntimes, eventually leads to put \"overflow\", possibly causing memory\ncorruption or crash.\n\nThe fwnode_handle_put() is a leftover from commit 905f88ccebb1 (\"media:\ni2c: ds90ub9x3: Fix sub-device matching\"), which changed the code\nrelated to the sd.fwnode, but missed removing these fwnode_handle_put()\ncalls."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable teardown path is reached only through local driver lifecycle operations \u2014 sysfs bind/unbind of the ds90ub913a/ds90ub953 i2c driver or module unload/reload. There is no network, adjacent-network, or physical-hotplug path to the FPD-Link serializer i2c device, which is statically instantiated by the ds90ub960 deserializer at its probe.\nAC:L - Each unbind/rebind cycle deterministically drops exactly one unowned reference on the serializer fwnode, so the attacker simply repeats the cycle 3-4 times until the refcount underflows; no race, timing window, or uncontrollable memory-layout condition is involved. Heap grooming of the freed device_node is likewise under attacker control between cycles.\nPR:L - Consistent with this repo\u0027s treatment of driver unbind/module-reload lifetime bugs, an unprivileged local user with access to the driver model is scored as low privileges rather than full administrative privilege. The attacker needs no capability specific to the media subsystem and no authentication beyond local account access.\nUI:N - The attacker performs the repeated unbind/bind operations themselves; no victim action, filesystem mount, or file open is required. The refcount underflow accumulates purely from attacker-initiated driver removals.\nS:U - The underflowed fwnode and the resulting use-after-free are both within the kernel\u0027s own security authority; there is no VM, IOMMU, or sandbox boundary crossed. This is a standard in-kernel memory-safety issue affecting the same security scope.\nC:H - The premature free of the device_node/fwnode leaves stale pointers in the i2c client device and in ds90ub960\u0027s rxport-\u003eser.fwnode, so subsequent fwnode property reads operate on reallocated attacker-groomed heap memory, enabling disclosure of arbitrary kernel data. Reference-count underflow leading to use-after-free is scored High per kernel guidance.\nI:H - struct fwnode_handle carries a const struct fwnode_operations *ops that every fwnode_call_*_op macro invokes indirectly, so a freed-and-resprayed node hands the attacker a controlled indirect-call primitive and thus control-flow hijacking. The commit message itself warns of \"memory corruption.\"\nA:H - Even on static device trees where the node is not actually freed, of_node_release() emits an error plus dump_stack() and the following put produces a \"refcount_t: underflow; use-after-free\" kobject WARN \u2014 an oops, and a full panic under panic_on_warn. On dynamic/overlay nodes the use-after-free crashes the kernel outright."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:47:21.273Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/474d7baf91d37bc411fa60de5bbf03c9dd82e18a"
        },
        {
          "url": "https://git.kernel.org/stable/c/f4e4373322f8d4c19721831f7fb989e52d30dab0"
        },
        {
          "url": "https://git.kernel.org/stable/c/70743d6a8b256225675711e7983825f1be86062d"
        },
        {
          "url": "https://git.kernel.org/stable/c/60b45ece41c5632a3a3274115a401cb244180646"
        }
      ],
      "title": "media: i2c: ds90ub9x3: Fix extra fwnode_handle_put()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-58003",
    "datePublished": "2025-02-27T02:12:00.834Z",
    "dateReserved": "2025-02-27T02:10:48.226Z",
    "dateUpdated": "2026-08-05T11:47:21.273Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…