We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-50058

serial: protect uart_port_dtr_rts() in uart_shutdown() too



Description

In the Linux kernel, the following vulnerability has been resolved: serial: protect uart_port_dtr_rts() in uart_shutdown() too Commit af224ca2df29 (serial: core: Prevent unsafe uart port access, part 3) added few uport == NULL checks. It added one to uart_shutdown(), so the commit assumes, uport can be NULL in there. But right after that protection, there is an unprotected "uart_port_dtr_rts(uport, false);" call. That is invoked only if HUPCL is set, so I assume that is the reason why we do not see lots of these reports. Or it cannot be NULL at this point at all for some reason :P. Until the above is investigated, stay on the safe side and move this dereference to the if too. I got this inconsistency from Coverity under CID 1585130. Thanks.

Reserved 2024-10-21 | Published 2024-10-21 | Updated 2024-12-19 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 2fe399bb8efd0d325ab1138cf8e3ecf23a39e96d
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 399927f0f875b93f3d5a0336d382ba48b8671eb2
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before d7b5876a6e74cdf8468a478be6b23f2f5464ac7a
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before e418d91195d29d5f9c9685ff309b92b04b41dc40
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 76ed24a34223bb2c6b6162e1d8389ec4e602a290
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 602babaa84d627923713acaf5f7e9a4369e77473
affected

Default status
affected

5.10.229
unaffected

5.15.170
unaffected

6.1.115
unaffected

6.6.57
unaffected

6.11.4
unaffected

6.12
unaffected

References

git.kernel.org/...c/2fe399bb8efd0d325ab1138cf8e3ecf23a39e96d

git.kernel.org/...c/399927f0f875b93f3d5a0336d382ba48b8671eb2

git.kernel.org/...c/d7b5876a6e74cdf8468a478be6b23f2f5464ac7a

git.kernel.org/...c/e418d91195d29d5f9c9685ff309b92b04b41dc40

git.kernel.org/...c/76ed24a34223bb2c6b6162e1d8389ec4e602a290

git.kernel.org/...c/602babaa84d627923713acaf5f7e9a4369e77473

cve.org (CVE-2024-50058)

nvd.nist.gov (CVE-2024-50058)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-50058

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.