CVE-2024-58034
Published: Feb 27, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: memory: tegra20-emc: fix an OF node reference bug in tegra_emc_find_node_by_ram_code() As of_find_node_by_name() release the reference of the argument device node, tegra_emc_find_node_by_ram_code() releases some device nodes while still in use, resulting in possible UAFs. According to the bindings and the in-tree DTS files, the "emc-tables" node is always device's child node with the property "nvidia,use-ram-code", and the "lpddr2" node is a child of the "emc-tables" node. Thus utilize the for_each_child_of_node() macro and of_get_child_by_name() instead of of_find_node_by_name() to simplify the code. This bug was found by an experimental verification tool that I am developing. [krzysztof: applied v1, adjust the commit msg to incorporate v2 parts]
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 96e5da7c842424bcf64afe1082b960b42b96190b - < c3def10c610ae046aaa61d00528e7bd15e4ad8d3affected 96e5da7c842424bcf64afe1082b960b42b96190b - < e9d07e91de140679eeaf275f47ad154467cb9e05affected 96e5da7c842424bcf64afe1082b960b42b96190b - < c144423cb07e4e227a8572d5742ca2b36ada770daffected 96e5da7c842424bcf64afe1082b960b42b96190b - < 3b02273446e23961d910b50cc12528faec649fb2affected 96e5da7c842424bcf64afe1082b960b42b96190b - < 755e44538c190c31de9090d8e8821d228fcfd416+1 more versions |
Linux | Linux | affected 5.0unaffected 0 - < 5.0unaffected 5.15.179 - <= 5.15.*unaffected 6.1.129 - <= 6.1.*unaffected 6.6.76 - <= 6.6.*+3 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now