cbcvebase.
CVE-2024-40903
published 2024-07-12

CVE-2024-40903: In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: fix use-after-free case in tcpm_register_source_caps There could be a…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.6th percentile
In the Linux kernel, the following vulnerability has been resolved:

usb: typec: tcpm: fix use-after-free case in tcpm_register_source_caps

There could be a potential use-after-free case in
tcpm_register_source_caps(). This could happen when:
* new (say invalid) source caps are advertised
* the existing source caps are unregistered
* tcpm_register_source_caps() returns with an error as
usb_power_delivery_register_capabilities() fails

This causes port->partner_source_caps to hold on to the now freed source
caps.

Reset port->partner_source_caps value to NULL after unregistering
existing source caps.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 230ecdf71a644c9c73e0e6735b33173074ae3f94 < 6b67b652849faf108a09647c7fde9b179ef24e2b6b67b652849faf108a09647c7fde9b179ef24e2b
linuxlinux>= 230ecdf71a644c9c73e0e6735b33173074ae3f94 < e7e921918d905544500ca7a95889f898121ba886e7e921918d905544500ca7a95889f898121ba886
linuxlinux>= 6.1.91 < 6.1.956.1.95
linuxlinux>= 6.6.31 < 6.6.356.6.35
linuxlinux>= 6.8.10 < 6.96.9
linuxlinux>= b16abab1fb645c4b7a86c357dc83a48cf21c2795 < 04c05d50fa79a41582f7bde8a1fd4377ae4a39e504c05d50fa79a41582f7bde8a1fd4377ae4a39e5
linuxlinux>= cfcd544a9974c6b6fb37ca385146e4796dcaf66d < 4053696594d7235f3638d49a00cf0f289e4b36a34053696594d7235f3638d49a00cf0f289e4b36a3
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.1.61 < 6.1.956.1.95
linuxlinux_kernel>= 6.6.31 < 6.6.356.6.35
linuxlinux_kernel>= 6.9 < 6.9.66.9.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.