cbcvebase.
CVE-2024-58093
published 2025-04-16

CVE-2024-58093: In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstream function removal Before 456d8aa37d0f…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstream function removal Before 456d8aa37d0f ("PCI/ASPM: Disable ASPM on MFD function removal to avoid use-after-free"), we would free the ASPM link only after the last function on the bus pertaining to the given link was removed. That was too late. If function 0 is removed before sibling function, link->downstream would point to free'd memory after. After above change, we freed the ASPM parent link state upon any function removal on the bus pertaining to a given link. That is too early. If the link is to a PCIe switch with MFD on the upstream port, then removing functions other than 0 first would free a link which still remains parent_link to the remaining downstream ports. The resulting GPFs are especially frequent during hot-unplug, because pciehp removes devices on the link bus in reverse order. On that switch, function 0 is the virtual P2P bridge to the internal bus. Free exactly when function 0 is removed -- before the parent link is obsolete, but after all subordinate links are gone. [kwilczynski: commit log]

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
googlechrome_chrome
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 < 8b930ddc2044e36866c41423e89889e0258695a38b930ddc2044e36866c41423e89889e0258695a3
linuxlinux>= 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 < f556b6ba0ac5f8353287ce6ed761228f0b4fafb7f556b6ba0ac5f8353287ce6ed761228f0b4fafb7
linuxlinux>= 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 < ba4cdc14c0d4df00d3e99bff7fe545303db98183ba4cdc14c0d4df00d3e99bff7fe545303db98183
linuxlinux>= 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 < 4d96930239981f312821a4065db8cc0f8240a1734d96930239981f312821a4065db8cc0f8240a173
linuxlinux>= 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 < cbf937dcadfd571a434f8074d057b32cd14fbea5cbf937dcadfd571a434f8074d057b32cd14fbea5
linuxlinux>= 5.10.188 < 5.10.2365.10.236
linuxlinux>= 5.15.121 < 5.15.1805.15.180
linuxlinux>= 5.4.251 < 5.4.2925.4.292
linuxlinux>= 6.1.39 < 6.1.1346.1.134
linuxlinux>= 6.3.13 < 6.46.4
linuxlinux>= 6.4.4 < 6.56.5
linuxlinux>= 666e7f9d60cee23077ea3e6331f6f8a19f7ea03f < 0a0f9aecf66b98959aab7fb5764b4b3e522f4f5b0a0f9aecf66b98959aab7fb5764b4b3e522f4f5b
linuxlinux>= 7aecdd47910c51707696e8b0e045b9f88bd4230f < cd4b07507794f7ad1a74e12eca75121d98187e66cd4b07507794f7ad1a74e12eca75121d98187e66
linuxlinux>= 7badf4d6f49a358a01ab072bbff88d3ee886c33b < 62db339ecc3d58d8fd83a9e4d80061cd943bb6e262db339ecc3d58d8fd83a9e4d80061cd943bb6e2
linuxlinux>= 9856c0de49052174ab474113f4ba40c02aaee086 < e5cd58f61e9d8024ee11bd78c12c8916891d4077e5cd58f61e9d8024ee11bd78c12c8916891d4077
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc6.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.