CVE-2024-35816

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-35816
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35816.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-35816
Downstream
Published
2024-05-17T13:23:21Z
Modified
2025-10-17T03:49:36.684775Z
Summary
firewire: ohci: prevent leak of left-over IRQ on unbind
Details

In the Linux kernel, the following vulnerability has been resolved:

firewire: ohci: prevent leak of left-over IRQ on unbind

Commit 5a95f1ded28691e6 ("firewire: ohci: use devres for requested IRQ") also removed the call to freeirq() in pciremove(), leading to a leftover irq of devmrequestirq() at pcidisablemsi() in pci_remove() when unbinding the driver from the device

removeprocentry: removing non-empty directory 'irq/136', leaking at least 'firewireohci' Call Trace: ? removeprocentry+0x19c/0x1c0 ? _warn+0x81/0x130 ? removeprocentry+0x19c/0x1c0 ? reportbug+0x171/0x1a0 ? consoleunlock+0x78/0x120 ? handlebug+0x3c/0x80 ? excinvalidop+0x17/0x70 ? asmexcinvalidop+0x1a/0x20 ? removeprocentry+0x19c/0x1c0 unregisterirqproc+0xf4/0x120 freedesc+0x3d/0xe0 ? kfree+0x29f/0x2f0 irqfreedescs+0x47/0x70 msidomainfreelocked.part.0+0x19d/0x1d0 msidomainfreeirqsalllocked+0x81/0xc0 pcifreemsiirqs+0x12/0x40 pcidisablemsi+0x4c/0x60 pciremove+0x9d/0xc0 [firewireohci 01b483699bebf9cb07a3d69df0aa2bee71db1b26] pcideviceremove+0x37/0xa0 devicereleasedriverinternal+0x19f/0x200 unbindstore+0xa1/0xb0

remove irq with devmfreeirq() before pcidisablemsi() also remove it in failmsi: of pciprobe() as this would lead to an identical leak

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5a95f1ded28691e69f7d6718c5dcbc149613d431
Fixed
43c70cbc2502cf2557105c662eeed6a15d082b88
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5a95f1ded28691e69f7d6718c5dcbc149613d431
Fixed
318f6d53dd425c400e35f1a9b7af682c2c6a66d6
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5a95f1ded28691e69f7d6718c5dcbc149613d431
Fixed
575801663c7dc38f826212b39e3b91a4a8661c33

Affected versions

v6.*

v6.4
v6.4-rc4
v6.4-rc5
v6.4-rc6
v6.4-rc7
v6.5
v6.5-rc1
v6.5-rc2
v6.5-rc3
v6.5-rc4
v6.5-rc5
v6.5-rc6
v6.5-rc7
v6.6
v6.6-rc1
v6.6-rc2
v6.6-rc3
v6.6-rc4
v6.6-rc5
v6.6-rc6
v6.6-rc7
v6.6.1
v6.6.10
v6.6.11
v6.6.12
v6.6.13
v6.6.14
v6.6.15
v6.6.16
v6.6.17
v6.6.18
v6.6.19
v6.6.2
v6.6.20
v6.6.21
v6.6.22
v6.6.23
v6.6.3
v6.6.4
v6.6.5
v6.6.6
v6.6.7
v6.6.8
v6.6.9
v6.7
v6.7-rc1
v6.7-rc2
v6.7-rc3
v6.7-rc4
v6.7-rc5
v6.7-rc6
v6.7-rc7
v6.7-rc8
v6.7.1
v6.7.10
v6.7.11
v6.7.2
v6.7.3
v6.7.4
v6.7.5
v6.7.6
v6.7.7
v6.7.8
v6.7.9
v6.8-rc1
v6.8-rc2
v6.8-rc3
v6.8-rc4
v6.8-rc5
v6.8-rc6
v6.8-rc7

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.5.0
Fixed
6.6.24
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.12