cbcvebase.
CVE-2024-58003
published 2025-02-27

CVE-2024-58003: In the Linux kernel, the following vulnerability has been resolved: media: i2c: ds90ub9x3: Fix extra fwnode_handle_put() The ub913 and ub953 drivers call…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
9.0th percentile
In the Linux kernel, the following vulnerability has been resolved: media: i2c: ds90ub9x3: Fix extra fwnode_handle_put() The ub913 and ub953 drivers call fwnode_handle_put(priv->sd.fwnode) as part of their remove process, and if the driver is removed multiple times, eventually leads to put "overflow", possibly causing memory corruption or crash. The fwnode_handle_put() is a leftover from commit 905f88ccebb1 ("media: i2c: ds90ub9x3: Fix sub-device matching"), which changed the code related to the sd.fwnode, but missed removing these fwnode_handle_put() calls.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.15-1 (forky)linux 6.12.15-1 (forky)
linuxlinux
linuxlinux>= 905f88ccebb14e42bcd19455b0d9c0d4808f1897 < 474d7baf91d37bc411fa60de5bbf03c9dd82e18a474d7baf91d37bc411fa60de5bbf03c9dd82e18a
linuxlinux>= 905f88ccebb14e42bcd19455b0d9c0d4808f1897 < f4e4373322f8d4c19721831f7fb989e52d30dab0f4e4373322f8d4c19721831f7fb989e52d30dab0
linuxlinux>= 905f88ccebb14e42bcd19455b0d9c0d4808f1897 < 70743d6a8b256225675711e7983825f1be86062d70743d6a8b256225675711e7983825f1be86062d
linuxlinux>= 905f88ccebb14e42bcd19455b0d9c0d4808f1897 < 60b45ece41c5632a3a3274115a401cb24418064660b45ece41c5632a3a3274115a401cb244180646
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 6.13 < 6.13.36.13.3
linuxlinux_kernel>= 6.6 < 6.6.786.6.78
linuxlinux_kernel>= 6.7 < 6.12.146.12.14

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.