cbcvebase.
CVE-2024-38611
published 2024-06-19

CVE-2024-38611: In the Linux kernel, the following vulnerability has been resolved: media: i2c: et8ek8: Don't strip remove function when driver is builtin Using __exit for the…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.6th percentile
In the Linux kernel, the following vulnerability has been resolved: media: i2c: et8ek8: Don't strip remove function when driver is builtin Using __exit for the remove function results in the remove callback being discarded with CONFIG_VIDEO_ET8EK8=y. When such a device gets unbound (e.g. using sysfs or hotplug), the driver is just removed without the cleanup being performed. This results in resource leaks. Fix it by compiling in the remove callback unconditionally. This also fixes a W=1 modpost warning: WARNING: modpost: drivers/media/i2c/et8ek8/et8ek8: section mismatch in reference: et8ek8_i2c_driver+0x10 (section: .data) -> et8ek8_remove (section: .exit.text)

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= c5254e72b8edc2ca0a98703e92e8c34959343d2c < 963523600d9f1e36bc35ba774c2493d6baa4dd8f963523600d9f1e36bc35ba774c2493d6baa4dd8f
linuxlinux>= c5254e72b8edc2ca0a98703e92e8c34959343d2c < ece3fc1c10197052044048bea4f13cfdcf25b416ece3fc1c10197052044048bea4f13cfdcf25b416
linuxlinux>= c5254e72b8edc2ca0a98703e92e8c34959343d2c < 04d1086a62ac492ebb6bb0c94c1c8cb55f5d1f3604d1086a62ac492ebb6bb0c94c1c8cb55f5d1f36
linuxlinux>= c5254e72b8edc2ca0a98703e92e8c34959343d2c < c1a3803e5bb91c13e9ad582003e4288f67f06cd9c1a3803e5bb91c13e9ad582003e4288f67f06cd9
linuxlinux>= c5254e72b8edc2ca0a98703e92e8c34959343d2c < 43fff07e4b1956d0e5cf23717507e438278ea3d943fff07e4b1956d0e5cf23717507e438278ea3d9
linuxlinux>= c5254e72b8edc2ca0a98703e92e8c34959343d2c < 904db2ba44ae60641b6378c5013254d09acf5e80904db2ba44ae60641b6378c5013254d09acf5e80
linuxlinux>= c5254e72b8edc2ca0a98703e92e8c34959343d2c < 545b215736c5c4b354e182d99c578a472ac9bfce545b215736c5c4b354e182d99c578a472ac9bfce
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.15.0-230.2424.15.0-230.242
linuxlinux_kernel>= 4.11 < 5.10.2365.10.236
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1336.1.133
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12
linuxlinux_kernel>= 6.9 < 6.9.36.9.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.