PT-2024-29188 · Lenovo+4 · Lenovo Yoga Tablet 2+4

Published

2024-04-15

·

Updated

2026-05-26

·

CVE-2024-40975

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises from the removal of devices while there are still consumers with a reference to the device. This is particularly problematic in the regulator subsystem. If a regulator is unregistered while drivers still hold a reference, a warning is triggered. The bq24190 charger chip provides a 5V boost converter output for powering USB devices, and its driver exports this as a Vbus regulator. The removal order of devices is crucial, especially on the Lenovo Yoga Tablet 2 series, where the regulator is controlled differently across models. To avoid similar problems, the solution involves changing the x86 android tablet remove function to unregister all device types in reverse order.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2026-01447
CVE-2024-40975
ECHO-DF74-3D96-4C99
OESA-2024-1897
SUSE-SU-2024:2802-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7008-1
USN-7029-1

Affected Products

Debian
Lenovo Yoga Tablet 2
Linuxmint
Suse
Ubuntu