CVE Database
/

CVE-2024-58003

Back to search

CVE-2024-58003

Published: Feb 27, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: media: i2c: ds90ub9x3: Fix extra fwnode_handle_put() The ub913 and ub953 drivers call fwnode_handle_put(priv->sd.fwnode) as part of their remove process, and if the driver is removed multiple times, eventually leads to put "overflow", possibly causing memory corruption or crash. The fwnode_handle_put() is a leftover from commit 905f88ccebb1 ("media: i2c: ds90ub9x3: Fix sub-device matching"), which changed the code related to the sd.fwnode, but missed removing these fwnode_handle_put() calls.

VendorProductVersions

Linux

Linux

affected
905f88ccebb14e42bcd19455b0d9c0d4808f1897 - < 474d7baf91d37bc411fa60de5bbf03c9dd82e18a
affected
905f88ccebb14e42bcd19455b0d9c0d4808f1897 - < f4e4373322f8d4c19721831f7fb989e52d30dab0
affected
905f88ccebb14e42bcd19455b0d9c0d4808f1897 - < 70743d6a8b256225675711e7983825f1be86062d
affected
905f88ccebb14e42bcd19455b0d9c0d4808f1897 - < 60b45ece41c5632a3a3274115a401cb244180646

Linux

Linux

affected
6.6
unaffected
0 - < 6.6
unaffected
6.6.78 - <= 6.6.*
unaffected
6.12.14 - <= 6.12.*
unaffected
6.13.3 - <= 6.13.*

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now