We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-50269

usb: musb: sunxi: Fix accessing an released usb phy



Description

In the Linux kernel, the following vulnerability has been resolved: usb: musb: sunxi: Fix accessing an released usb phy Commit 6ed05c68cbca ("usb: musb: sunxi: Explicitly release USB PHY on exit") will cause that usb phy @glue->xceiv is accessed after released. 1) register platform driver @sunxi_musb_driver // get the usb phy @glue->xceiv sunxi_musb_probe() -> devm_usb_get_phy(). 2) register and unregister platform driver @musb_driver musb_probe() -> sunxi_musb_init() use the phy here //the phy is released here musb_remove() -> sunxi_musb_exit() -> devm_usb_put_phy() 3) register @musb_driver again musb_probe() -> sunxi_musb_init() use the phy here but the phy has been released at 2). ... Fixed by reverting the commit, namely, removing devm_usb_put_phy() from sunxi_musb_exit().

Reserved 2024-10-21 | Published 2024-11-19 | Updated 2024-12-19 | Assigner Linux

Product status

Default status
unaffected

6ed05c68cbcae42cd52b8e53b66952bfa9c002ce before 721ddad945596220c123eb6f7126729fe277ee4f
affected

6ed05c68cbcae42cd52b8e53b66952bfa9c002ce before 4aa77d5ea9944468e16c3eed15e858fd5de44de1
affected

6ed05c68cbcae42cd52b8e53b66952bfa9c002ce before 6e2848d1c8c0139161e69ac0a94133e90e9988e8
affected

6ed05c68cbcae42cd52b8e53b66952bfa9c002ce before 63559ba8077cbadae1c92a65b73ea522bf377dd9
affected

6ed05c68cbcae42cd52b8e53b66952bfa9c002ce before ccd811c304d2ee56189bfbc49302cb3c44361893
affected

6ed05c68cbcae42cd52b8e53b66952bfa9c002ce before 8a30da5aa9609663b3e05bcc91a916537f66a4cd
affected

6ed05c68cbcae42cd52b8e53b66952bfa9c002ce before b08baa75b989cf779cbfa0969681f8ba2dc46569
affected

6ed05c68cbcae42cd52b8e53b66952bfa9c002ce before 498dbd9aea205db9da674994b74c7bf8e18448bd
affected

Default status
affected

4.14
affected

Any version before 4.14
unaffected

4.19.324
unaffected

5.4.286
unaffected

5.10.230
unaffected

5.15.172
unaffected

6.1.117
unaffected

6.6.61
unaffected

6.11.8
unaffected

6.12
unaffected

References

git.kernel.org/...c/721ddad945596220c123eb6f7126729fe277ee4f

git.kernel.org/...c/4aa77d5ea9944468e16c3eed15e858fd5de44de1

git.kernel.org/...c/6e2848d1c8c0139161e69ac0a94133e90e9988e8

git.kernel.org/...c/63559ba8077cbadae1c92a65b73ea522bf377dd9

git.kernel.org/...c/ccd811c304d2ee56189bfbc49302cb3c44361893

git.kernel.org/...c/8a30da5aa9609663b3e05bcc91a916537f66a4cd

git.kernel.org/...c/b08baa75b989cf779cbfa0969681f8ba2dc46569

git.kernel.org/...c/498dbd9aea205db9da674994b74c7bf8e18448bd

cve.org (CVE-2024-50269)

nvd.nist.gov (CVE-2024-50269)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-50269

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.