cbcvebase.
CVE-2024-50150
published 2024-11-07

CVE-2024-50150: In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmode should keep reference to parent The altmode device release refers to…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.7th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmode should keep reference to parent The altmode device release refers to its parent device, but without keeping a reference to it. When registering the altmode, get a reference to the parent and put it in the release function. Before this fix, when using CONFIG_DEBUG_KOBJECT_RELEASE, we see issues like this: [ 43.572860] kobject: 'port0.0' (ffff8880057ba008): kobject_release, parent 0000000000000000 (delayed 3000) [ 43.573532] kobject: 'port0.1' (ffff8880057bd008): kobject_release, parent 0000000000000000 (delayed 1000) [ 43.574407] kobject: 'port0' (ffff8880057b9008): kobject_release, parent 0000000000000000 (delayed 3000) [ 43.575059] kobject: 'port1.0' (ffff8880057ca008): kobject_release, parent 0000000000000000 (delayed 4000) [ 43.575908] kobject: 'port1.1' (ffff8880057c9008): kobject_release, parent 0000000000000000 (delayed 4000) [ 43.576908] kobject: 'typec' (ffff8880062dbc00): kobject_release, parent 0000000000000000 (delayed 4000) [ 43.577769] kobject: 'port1' (ffff8880057bf008): kobject_release, parent 0000000000000000 (delayed 3000) [ 46.612867] ================================================================== [ 46.613402] BUG: KASAN: slab-use-after-free in typec_altmode_release+0x38/0x129 [ 46.614003] Read of size 8 at addr ffff8880057b9118 by task kworker/2:1/48 [ 46.614538] [ 46.614668] CPU: 2 UID: 0 PID: 48 Comm: kworker/2:1 Not tainted 6.12.0-rc1-00138-gedbae730ad31 #535 [ 46.615391] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014 [ 46.616042] Workqueue: events kobject_delayed_cleanup [ 46.616446] Call Trace: [ 46.616648] [ 46.616820] dump_stack_lvl+0x5b/0x7c [ 46.617112] ? typec_altmode_release+0x38/0x129 [ 46.617470] print_report+0x14c/0x49e [ 46.617769] ? rcu_read_unlock_sched+0x56/0x69 [ 46.618117] ? __virt_addr_valid+0x19a/0x1ab [ 46.618456] ? kmem_cache_debug_flags+0xc/0x1d [ 46.618807] ? typec_altmode_release+0x38/0x129 [ 46.6

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7 < 2b0b33e8a58388fa9078f0fbe9af1900e6b088792b0b33e8a58388fa9078f0fbe9af1900e6b08879
linuxlinux>= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7 < 2c15c4133d00f5da632fce60ed013fc31aa9aa582c15c4133d00f5da632fce60ed013fc31aa9aa58
linuxlinux>= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7 < 6af43ec3bf40f8b428d9134ffa7a291aecd60da86af43ec3bf40f8b428d9134ffa7a291aecd60da8
linuxlinux>= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7 < 87474406056891e4fdea0794e1f632b21b3dfa2787474406056891e4fdea0794e1f632b21b3dfa27
linuxlinux>= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7 < bee1b68cb8bcee4fd3a8bde3a4886e0b1375dc4dbee1b68cb8bcee4fd3a8bde3a4886e0b1375dc4d
linuxlinux>= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7 < 1ded6b12499e6dee9b0e1ceac633be36538f6fc21ded6b12499e6dee9b0e1ceac633be36538f6fc2
linuxlinux>= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7 < 68a7c7fe322546be1464174c8d85874b8161deda68a7c7fe322546be1464174c8d85874b8161deda
linuxlinux>= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7 < befab3a278c59db0cc88c8799638064f6d3fd6f8befab3a278c59db0cc88c8799638064f6d3fd6f8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.6-16.11.6-1
linuxlinux_kernel>= 0 < 6.11.6-16.11.6-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.19 < 4.19.3234.19.323
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1705.15.170
linuxlinux_kernel>= 5.16 < 6.1.1156.1.115
linuxlinux_kernel>= 5.5 < 5.10.2295.10.229

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.