cbcvebase.
CVE-2024-58084
published 2025-03-06

CVE-2024-58084: In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix missing read barrier in qcom_scm_get_tzmem_pool() Commit…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.2th percentile
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix missing read barrier in qcom_scm_get_tzmem_pool() Commit 2e4955167ec5 ("firmware: qcom: scm: Fix __scm and waitq completion variable initialization") introduced a write barrier in probe function to store global '__scm' variable. We all known barriers are paired (see memory-barriers.txt: "Note that write barriers should normally be paired with read or address-dependency barriers"), therefore accessing it from concurrent contexts requires read barrier. Previous commit added such barrier in qcom_scm_is_available(), so let's use that directly. Lack of this read barrier can result in fetching stale '__scm' variable value, NULL, and dereferencing it. Note that barrier in qcom_scm_is_available() satisfies here the control dependency.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.15-1 (forky)linux 6.12.15-1 (forky)
linuxlinux
linuxlinux>= 449d0d84bcd8246b508d07995326d13c54488b8c < fee921e3c641f64185abee83f9a6e65f0b380682fee921e3c641f64185abee83f9a6e65f0b380682
linuxlinux>= 449d0d84bcd8246b508d07995326d13c54488b8c < e03db7c1255ebabba5e1a447754faeb138de15a2e03db7c1255ebabba5e1a447754faeb138de15a2
linuxlinux>= 449d0d84bcd8246b508d07995326d13c54488b8c < b628510397b5cafa1f5d3e848a28affd1c635302b628510397b5cafa1f5d3e848a28affd1c635302
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel6.11 – 6.12.14
linuxlinux_kernel6.13 – 6.13.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.