PT-2024-6603 · Linux+6 · Linux Kernel+6

Amit Sunil Dhamne

·

Published

2024-06-04

·

Updated

2025-09-29

·

CVE-2024-40903

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to a potential use-after-free case in the tcpm register source caps() function. This could happen when new source caps are advertised, existing source caps are unregistered, and tcpm register source caps() returns with an error due to usb power delivery register capabilities() failing. As a result, port->partner source caps holds on to the now freed source caps. The problem can be resolved by resetting the port->partner source caps value to NULL after unregistering existing source caps.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-10855
ALT-PU-2024-11524
ALT-PU-2024-14046
BDU:2024-07750
CVE-2024-40903
DLA-4008-1
DSA-5731-1
INFSA-2024_9315
OPENSUSE-SU-2024_2947-1
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:2894-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7008-1
USN-7029-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu