CVE-2024-50176 — Improper Handling of Exceptional Conditions in Linux
Severity
5.5MEDIUMNVD
OSV8.8
EPSS
0.0%
top 98.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 8
Latest updateApr 1
Description
In the Linux kernel, the following vulnerability has been resolved:
remoteproc: k3-r5: Fix error handling when power-up failed
By simply bailing out, the driver was violating its rule and internal
assumptions that either both or no rproc should be initialized. E.g.,
this could cause the first core to be available but not the second one,
leading to crashes on its shutdown later on while trying to dereference
that second instance.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages6 packages
▶CVEListV5linux/linux2a1ec20b174c0f613224c59e694639ac07308b53 — 87ab3af7447791d0c619610fd560bd804549e187+6