CVE-2024-35879
Published: May 19, 2024
Modified: May 23, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: of: dynamic: Synchronize of_changeset_destroy() with the devlink removals In the following sequence: 1) of_platform_depopulate() 2) of_overlay_remove() During the step 1, devices are destroyed and devlinks are removed. During the step 2, OF nodes are destroyed but __of_changeset_entry_destroy() can raise warnings related to missing of_node_put(): ERROR: memory leak, expected refcount 1 instead of 2 ... Indeed, during the devlink removals performed at step 1, the removal itself releasing the device (and the attached of_node) is done by a job queued in a workqueue and so, it is done asynchronously with respect to function calls. When the warning is present, of_node_put() will be called but wrongly too late from the workqueue job. In order to be sure that any ongoing devlink removals are done before the of_node destruction, synchronize the of_changeset_destroy() with the devlink removals.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected d007150b4e15bfcb8d36cfd88a5645d42e44d383 - < 3127b2ee50c424a96eb3559fbb7b43cf0b111c7aaffected 80dd33cf72d1ab4f0af303f1fa242c6d6c8d328f - < 3ee2424107546d882e1ddd75333ca9c32879908caffected 80dd33cf72d1ab4f0af303f1fa242c6d6c8d328f - < 7b6df050c45a1ea158fd50bc32a8e1447dd1e951affected 80dd33cf72d1ab4f0af303f1fa242c6d6c8d328f - < 801c8b8ec5bfb3519566dff16a5ecd48302fca82affected 80dd33cf72d1ab4f0af303f1fa242c6d6c8d328f - < ae6d76e4f06c37a623e357e79d49b17411db6f5c+4 more versions |
Linux | Linux | affected 5.13unaffected 0 - < 5.13unaffected 5.10.215 - <= 5.10.*unaffected 5.15.154 - <= 5.15.*unaffected 6.1.85 - <= 6.1.*+3 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now