CVE-2024-35816

Source
https://cve.org/CVERecord?id=CVE-2024-35816
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35816.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-35816
Downstream
Published
2024-05-17T13:23:21.051Z
Modified
2026-03-20T12:36:40.026223Z
Summary
firewire: ohci: prevent leak of left-over IRQ on unbind
Details

In the Linux kernel, the following vulnerability has been resolved:

firewire: ohci: prevent leak of left-over IRQ on unbind

Commit 5a95f1ded28691e6 ("firewire: ohci: use devres for requested IRQ") also removed the call to freeirq() in pciremove(), leading to a leftover irq of devmrequestirq() at pcidisablemsi() in pci_remove() when unbinding the driver from the device

removeprocentry: removing non-empty directory 'irq/136', leaking at least 'firewireohci' Call Trace: ? removeproc_entry+0x19c/0x1c0 ? __warn+0x81/0x130 ? removeprocentry+0x19c/0x1c0 ? reportbug+0x171/0x1a0 ? consoleunlock+0x78/0x120 ? handlebug+0x3c/0x80 ? excinvalidop+0x17/0x70 ? asmexcinvalidop+0x1a/0x20 ? removeprocentry+0x19c/0x1c0 unregisterirqproc+0xf4/0x120 freedesc+0x3d/0xe0 ? kfree+0x29f/0x2f0 irqfreedescs+0x47/0x70 msidomainfreelocked.part.0+0x19d/0x1d0 msidomainfreeirqsalllocked+0x81/0xc0 pcifreemsiirqs+0x12/0x40 pcidisablemsi+0x4c/0x60 pciremove+0x9d/0xc0 [firewireohci 01b483699bebf9cb07a3d69df0aa2bee71db1b26] pcideviceremove+0x37/0xa0 devicereleasedriverinternal+0x19f/0x200 unbindstore+0xa1/0xb0

remove irq with devmfreeirq() before pcidisablemsi() also remove it in failmsi: of pciprobe() as this would lead to an identical leak

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35816.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5a95f1ded28691e69f7d6718c5dcbc149613d431
Fixed
43c70cbc2502cf2557105c662eeed6a15d082b88
Fixed
318f6d53dd425c400e35f1a9b7af682c2c6a66d6
Fixed
575801663c7dc38f826212b39e3b91a4a8661c33

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35816.json"