CVE-2024-49925

Source
https://cve.org/CVERecord?id=CVE-2024-49925
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-49925.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-49925
Downstream
Related
Published
2024-10-21T18:01:49.732Z
Modified
2026-05-18T05:59:01.232950564Z
Summary
fbdev: efifb: Register sysfs groups through driver core
Details

In the Linux kernel, the following vulnerability has been resolved:

fbdev: efifb: Register sysfs groups through driver core

The driver core can register and cleanup sysfs groups already. Make use of that functionality to simplify the error handling and cleanup.

Also avoid a UAF race during unregistering where the sysctl attributes were usable after the info struct was freed.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/49xxx/CVE-2024-49925.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
753375a881caa01112b7cec2c796749154e0bb23
Fixed
2a9c40c72097b583b23aeb2a26d429ccfc81fbc1
Fixed
36bfefb6baaa8e46de44f4fd919ce4347337620f
Fixed
872cd2d029d2c970a8a1eea88b48dab2b3f2e93a
Fixed
4684d69b9670a83992189f6271dc0fcdec4ed0d7
Fixed
95cdd538e0e5677efbdf8aade04ec098ab98f457

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-49925.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
6.1.120
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.55
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.10.14
Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.11.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-49925.json"