CVE-2024-27049

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925e: fix use-after-free in free_irq() From commit a304e1b82808 ("[PATCH] Debug shared irqs"), there is a test to make sure the shared irq handler should be able to handle the unexpected event after deregistration. For this case, let's apply MT76_REMOVED flag to indicate the device was removed and do not run into the resource access anymore.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Dec 2024, 19:11

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-416
References () https://git.kernel.org/stable/c/6d9930096e1f13cf6d9aabfbf95d0e05fb04144f - () https://git.kernel.org/stable/c/6d9930096e1f13cf6d9aabfbf95d0e05fb04144f - Patch
References () https://git.kernel.org/stable/c/84470b48af03a818039d587478b415cbcb264ff5 - () https://git.kernel.org/stable/c/84470b48af03a818039d587478b415cbcb264ff5 - Patch
References () https://git.kernel.org/stable/c/a5a5f4413d91f395cb2d89829d376d7393ad48b9 - () https://git.kernel.org/stable/c/a5a5f4413d91f395cb2d89829d376d7393ad48b9 - Patch
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

21 Nov 2024, 09:03

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux se ha resuelto la siguiente vulnerabilidad: wifi: mt76: mt7925e: fix use-after-free in free_irq() Desde el commit a304e1b82808 ("[PATCH] Depurar irqs compartidas"), existe una prueba para asegurarse de que El controlador de irq compartido debería poder manejar el evento inesperado después de la cancelación del registro. Para este caso, apliquemos el indicador MT76_REMOVED para indicar que el dispositivo fue eliminado y que ya no se puede acceder al recurso.
References () https://git.kernel.org/stable/c/6d9930096e1f13cf6d9aabfbf95d0e05fb04144f - () https://git.kernel.org/stable/c/6d9930096e1f13cf6d9aabfbf95d0e05fb04144f -
References () https://git.kernel.org/stable/c/84470b48af03a818039d587478b415cbcb264ff5 - () https://git.kernel.org/stable/c/84470b48af03a818039d587478b415cbcb264ff5 -
References () https://git.kernel.org/stable/c/a5a5f4413d91f395cb2d89829d376d7393ad48b9 - () https://git.kernel.org/stable/c/a5a5f4413d91f395cb2d89829d376d7393ad48b9 -

01 May 2024, 19:50

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-01 13:15

Updated : 2024-12-23 19:11


NVD link : CVE-2024-27049

Mitre link : CVE-2024-27049

CVE.ORG link : CVE-2024-27049


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free