cbcvebase.
CVE-2024-35790
published 2024-05-17

CVE-2024-35790: In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group The DisplayPort driver's sysfs nodes may be present to the userspace before typec_altmode_set_drvdata() completes in dp_altmode_probe. This means that a sysfs read can trigger a NULL pointer error by deferencing dp->hpd in hpd_show or dp->lock in pin_assignment_show, as dev_get_drvdata() returns NULL in those cases. Remove manual sysfs node creation in favor of adding attribute group as default for devices bound to the driver. The ATTRIBUTE_GROUPS() macro is not used here otherwise the path to the sysfs nodes is no longer compliant with the ABI.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux>= 0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 < 6b989ea1c479533ab8dbfbeb1704c94b1d3320da6b989ea1c479533ab8dbfbeb1704c94b1d3320da
linuxlinux>= 0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 < 9794ffd9d0c39ee070fbd733f862bbe89b28ba339794ffd9d0c39ee070fbd733f862bbe89b28ba33
linuxlinux>= 0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 < f1c5ddaef506e3517dce338c08a60663b1521920f1c5ddaef506e3517dce338c08a60663b1521920
linuxlinux>= 0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 < 4a22aeac24d0d5f26ba741408e8b5a4be6dc5dc04a22aeac24d0d5f26ba741408e8b5a4be6dc5dc0
linuxlinux>= 0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 < 0ad011776c057ce881b7fd6d8c79ecd459c087e90ad011776c057ce881b7fd6d8c79ecd459c087e9
linuxlinux>= 0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 < 165376f6b23e9a779850e750fb2eb06622e5a531165376f6b23e9a779850e750fb2eb06622e5a531
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 4.19 < 6.6.246.6.24
linuxlinux_kernel>= 6.7 < 6.7.126.7.12
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv9.1CRITICAL
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.