PT-2024-8422 · Linux+7 · Linux Kernel+7

Paul Menzel

·

Published

2024-04-03

·

Updated

2025-09-29

·

CVE-2024-35824

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the lis3lv02d i2c component in the Linux kernel, where the lis3lv02d i2c suspend() function calls lis3lv02d poweroff() even if the device has already been turned off by the runtime-suspend handler. This can cause unbalanced disables for the regulator, leading to a warning in the regulator core. The lis3lv02d i2c resume() function has similar issues, where it always powers on the device if it is runtime suspended, causing the enabled count for the regulator to increase by 1 every suspend/resume. These unbalanced regulator enable calls can cause the regulator to never be turned off and trigger a warning on driver unbind.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:5101
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-09981
CESA-2024_5101
CVE-2024-35824
INFSA-2024_5101
INFSA-2024_9315
RHSA-2024:5101
RHSA-2024:9315
RHSA-2024_5101
RHSA-2024_9315
RHSA-2025:1658
RLSA-2024:5101
RXSA-2024:5101
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1

Affected Products

Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse