PT-2025-9960 · Linux+6 · Linux Kernel+6
Ricardo Ribalda
·
Published
2024-12-19
·
Updated
2026-04-20
·
CVE-2024-58079
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A crash can occur in the Linux kernel during the unbind process of a device if a gpio unit is in use. This happens because the wrong device is used for device managed functions, specifically using the usb device instead of the interface device. As a result, cleanup functions are not called when the driver is unbound from the usb interface, leading to an IRQ that is never disabled. If an IRQ is triggered, it attempts to access memory sections that have already been freed, causing an error. The impact of this issue is limited, affecting only devices with gpio units and requiring the user to unbind the device, as a disconnect does not trigger this error.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu