CVE-2024-37021
Last modified
CVE-2024-37021 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: fpga: manager: add owner module and take its refcount The current implementation of the fpga manager assumes that the low-level module registers a driver for the parent device and uses its owner pointer to take the module's refcount. This approach is problematic since it can lead to a null pointer dereference while attempting to get the manager if the parent device does not have a driver. To address this problem, add a module owner pointer to the fpga_manager struct and use it to take the module's refcount. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: fpga: manager: add owner module and take its refcount The current implementation of the fpga manager assumes that the low-level module registers a driver for the parent device and uses its owner pointer to take the module's refcount. This approach is problematic since it can lead to a null pointer dereference while attempting to get the manager if the parent device does not have a driver. To address this problem, add a module owner pointer to the fpga_manager struct and use it to take the module's refcount. Modify the functions for registering the manager to take an additional owner module parameter and rename them to avoid conflicts. Use the old function names for helper macros that automatically set the module that registers the manager as the owner. This ensures compatibility with existing low-level control modules and reduces the chances of registering a manager without setting the owner. Also, update the documentation to keep it consistent with the new interface for registering an fpga manager. Other changes: opportunistically move put_device() from __fpga_mgr_get() to fpga_mgr_get() and of_fpga_mgr_get() to improve code clarity since the manager device is taken in these functions.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.4, < 6.1.120 |
| Linux | Linux Kernel | >= 6.2, < 6.6.33 |
| Linux | Linux Kernel | >= 6.7, < 6.9.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-37021?
How severe is CVE-2024-37021?
How do I fix CVE-2024-37021?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-37016Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentic…6.8
- CVE-2024-37017asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer ove…8.1
- CVE-2024-37018The OpenDaylight 0.15.3 controller allows topology poisoning…9.1
- CVE-2024-37019Northern.tech Mender Enterprise before 3.6.4 and 3.7.x befor…9.8
- CVE-2024-3702Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-37020Sequence of processor instructions leads to unexpected behav…4.8
- CVE-2024-37022Fuji Electric Tellus Lite V-Simulator is vulnerable to an o…7.8
- CVE-2024-37023Multiple OS command injection vulnerabilities affecting Vone…9.9
- CVE-2024-37024Uncontrolled search path for some ACAT software maintained b…6.7
- CVE-2024-37025Incorrect execution-assigned permissions in some Intel(R) Ad…6.7
- CVE-2024-37026In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-37027Improper Input validation in some Intel(R) VTune(TM) Profile…6.1
Are you affected by CVE-2024-37021?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
