CVE-2024-44967

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/09/2024
Last modified:
03/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/mgag200: Bind I2C lifetime to DRM device<br /> <br /> Managed cleanup with devm_add_action_or_reset() will release the I2C<br /> adapter when the underlying Linux device goes away. But the connector<br /> still refers to it, so this cleanup leaves behind a stale pointer<br /> in struct drm_connector.ddc.<br /> <br /> Bind the lifetime of the I2C adapter to the connector&amp;#39;s lifetime by<br /> using DRM&amp;#39;s managed release. When the DRM device goes away (after<br /> the Linux device) DRM will first clean up the connector and then<br /> clean up the I2C adapter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.0 (including) 6.1.105 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.46 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.10.5 (excluding)