PT-2024-29188 · Lenovo+4 · Lenovo Yoga Tablet 2+4
Published
2024-04-15
·
Updated
2026-05-26
·
CVE-2024-40975
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue arises from the removal of devices while there are still consumers with a reference to the device. This is particularly problematic in the regulator subsystem. If a regulator is unregistered while drivers still hold a reference, a warning is triggered. The bq24190 charger chip provides a 5V boost converter output for powering USB devices, and its driver exports this as a Vbus regulator. The removal order of devices is crucial, especially on the Lenovo Yoga Tablet 2 series, where the regulator is controlled differently across models. To avoid similar problems, the solution involves changing the x86 android tablet remove function to unregister all device types in reverse order.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Lenovo Yoga Tablet 2
Linuxmint
Suse
Ubuntu