CVE-2024-26963

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3-am62: fix module unload/reload behavior As runtime PM is enabled, the module can be runtime suspended when .remove() is called. Do a pm_runtime_get_sync() to make sure module is active before doing any register operations. Doing a pm_runtime_put_sync() should disable the refclk so no need to disable it again. Fixes the below warning at module removel. [ 39.705310] ------------[ cut here ]------------ [ 39.710004] clk:162:3 already disabled [ 39.713941] WARNING: CPU: 0 PID: 921 at drivers/clk/clk.c:1090 clk_core_disable+0xb0/0xb8 We called of_platform_populate() in .probe() so call the cleanup function of_platform_depopulate() in .remove(). Get rid of the now unnnecessary dwc3_ti_remove_core(). Without this, module re-load doesn't work properly.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

18 Sep 2025, 14:09

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/3895780fabd120d0fbd54354014e85207b25687c - () https://git.kernel.org/stable/c/3895780fabd120d0fbd54354014e85207b25687c - Patch
References () https://git.kernel.org/stable/c/629b534c42d04f0797980f2d1ed105fdb8906975 - () https://git.kernel.org/stable/c/629b534c42d04f0797980f2d1ed105fdb8906975 - Patch
References () https://git.kernel.org/stable/c/6661befe41009c210efa2c1bcd16a5cc4cff8a06 - () https://git.kernel.org/stable/c/6661befe41009c210efa2c1bcd16a5cc4cff8a06 - Patch
References () https://git.kernel.org/stable/c/6c6a45645a2e6a272dfde14eddbb6706de63c25d - () https://git.kernel.org/stable/c/6c6a45645a2e6a272dfde14eddbb6706de63c25d - Patch
References () https://git.kernel.org/stable/c/7dfed9855397d0df4c6f748d1f66547ab3bad766 - () https://git.kernel.org/stable/c/7dfed9855397d0df4c6f748d1f66547ab3bad766 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CWE NVD-CWE-noinfo

21 Nov 2024, 09:03

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/3895780fabd120d0fbd54354014e85207b25687c - () https://git.kernel.org/stable/c/3895780fabd120d0fbd54354014e85207b25687c -
References () https://git.kernel.org/stable/c/629b534c42d04f0797980f2d1ed105fdb8906975 - () https://git.kernel.org/stable/c/629b534c42d04f0797980f2d1ed105fdb8906975 -
References () https://git.kernel.org/stable/c/6661befe41009c210efa2c1bcd16a5cc4cff8a06 - () https://git.kernel.org/stable/c/6661befe41009c210efa2c1bcd16a5cc4cff8a06 -
References () https://git.kernel.org/stable/c/6c6a45645a2e6a272dfde14eddbb6706de63c25d - () https://git.kernel.org/stable/c/6c6a45645a2e6a272dfde14eddbb6706de63c25d -
References () https://git.kernel.org/stable/c/7dfed9855397d0df4c6f748d1f66547ab3bad766 - () https://git.kernel.org/stable/c/7dfed9855397d0df4c6f748d1f66547ab3bad766 -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: usb: dwc3-am62: corrige el comportamiento de descarga/recarga del módulo. Como el PM en tiempo de ejecución está habilitado, el tiempo de ejecución del módulo se puede suspender cuando se llama a .remove(). Realice pm_runtime_get_sync() para asegurarse de que el módulo esté activo antes de realizar cualquier operación de registro. Hacer pm_runtime_put_sync() debería deshabilitar refclk, por lo que no es necesario deshabilitarlo nuevamente. Corrige la siguiente advertencia al eliminar el módulo. [39.705310] ------------[ cortar aquí ]------------ [ 39.710004] clk:162:3 ya deshabilitado [ 39.713941] ADVERTENCIA: CPU: 0 PID : 921 en drivers/clk/clk.c:1090 clk_core_disable+0xb0/0xb8 Llamamos a of_platform_populate() en .probe(), así que llame a la función de limpieza of_platform_depopulate() en .remove(). Deshágase del ahora innecesario dwc3_ti_remove_core(). Sin esto, la recarga del módulo no funciona correctamente.

01 May 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-01 06:15

Updated : 2025-09-18 14:09


NVD link : CVE-2024-26963

Mitre link : CVE-2024-26963

CVE.ORG link : CVE-2024-26963


JSON object : View

Products Affected

linux

  • linux_kernel