CVE-2024-35879

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-35879
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35879.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-35879
Downstream
Related
Published
2024-05-19T09:15:09Z
Modified
2025-08-09T20:01:27Z
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

of: dynamic: Synchronize ofchangesetdestroy() with the devlink removals

In the following sequence: 1) ofplatformdepopulate() 2) ofoverlayremove()

During the step 1, devices are destroyed and devlinks are removed. During the step 2, OF nodes are destroyed but _ofchangesetentrydestroy() can raise warnings related to missing ofnodeput(): ERROR: memory leak, expected refcount 1 instead of 2 ...

Indeed, during the devlink removals performed at step 1, the removal itself releasing the device (and the attached ofnode) is done by a job queued in a workqueue and so, it is done asynchronously with respect to function calls. When the warning is present, ofnode_put() will be called but wrongly too late from the workqueue job.

In order to be sure that any ongoing devlink removals are done before the ofnode destruction, synchronize the ofchangeset_destroy() with the devlink removals.

References

Affected packages