cbcvebase.
CVE-2024-49874
published 2024-10-21

CVE-2024-49874: In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: Fix use after free vulnerability in svc_i3c_master Driver Due to Race…

PriorityP431high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.23%
13.8th percentile
In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: Fix use after free vulnerability in svc_i3c_master Driver Due to Race Condition In the svc_i3c_master_probe function, &master->hj_work is bound with svc_i3c_master_hj_work, &master->ibi_work is bound with svc_i3c_master_ibi_work. And svc_i3c_master_ibi_work can start the hj_work, svc_i3c_master_irq_handler can start the ibi_work. If we remove the module which will call svc_i3c_master_remove to make cleanup, it will free master->base through i3c_master_unregister while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | svc_i3c_master_hj_work svc_i3c_master_remove | i3c_master_unregister(&master->base)| device_unregister(&master->dev) | device_release | //free master->base | | i3c_master_do_daa(&master->base) | //use master->base Fix it by ensuring that the work is canceled before proceeding with the cleanup in svc_i3c_master_remove.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.4-1 (forky)linux 6.11.4-1 (forky)
linuxlinux
linuxlinux>= 0f74f8b6675cc36d689abb4d9b3d75ab4049b7d7 < 4ac637122930cc4ab7e2c22e364cf3aaf96b05b14ac637122930cc4ab7e2c22e364cf3aaf96b05b1
linuxlinux>= 0f74f8b6675cc36d689abb4d9b3d75ab4049b7d7 < 4318998892bf8fe99f97bea18c37ae7b685af75a4318998892bf8fe99f97bea18c37ae7b685af75a
linuxlinux>= 0f74f8b6675cc36d689abb4d9b3d75ab4049b7d7 < 27b55724d3f781dd6e635e89dc6e2fd78fa81a0027b55724d3f781dd6e635e89dc6e2fd78fa81a00
linuxlinux>= 0f74f8b6675cc36d689abb4d9b3d75ab4049b7d7 < 61850725779709369c7e907ae8c7c75dc7cec4f361850725779709369c7e907ae8c7c75dc7cec4f3
linuxlinux>= 87e0f28eda36c7843523aa8dd0c5dab3331e9718 < 56bddf543d4d7ddeff3f87b554ddacfdf086bffe56bddf543d4d7ddeff3f87b554ddacfdf086bffe
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.11 < 6.11.36.11.3
linuxlinux_kernel>= 6.4 < 6.6.556.6.55
linuxlinux_kernel>= 6.7 < 6.10.146.10.14
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.56.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.0LOW
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.