EN

Tracker / CVE-2024-43830

CVE-2024-43830

Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: leds: trigger: Unregister sysfs attributes before calling deactivate() Triggers which have trigger specific sysfs attributes typically store related data in trigger-data allocated by the activate() callback and freed by the deactivate() callback. Calling device_remove_groups() after calling deactivate() leaves a window where the sysfs attributes show/store functions could be called after deactivation and then operate on the just freed trigger-data. Move the device_remove_groups() call to before deactivate() to close this race window. This also makes the deactivation path properly do things in reverse order of the activation path which calls the activate() callback before calling device_add_groups().

Prodotti e versioni affette

linux linux_kernel · 4.19 → 4.19.320
linux linux_kernel · 4.20 → 5.4.282
linux linux_kernel · 5.11 → 5.15.165
linux linux_kernel · 5.16 → 6.1.103
linux linux_kernel · 5.5 → 5.10.224
linux linux_kernel · 6.2 → 6.6.44
linux linux_kernel · 6.7 → 6.10.3

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti