CVE-2024-27027: dpll: fix dpll_xa_ref_*_del() for multiple registrations
In the Linux kernel, the following vulnerability has been resolved:
dpll: fix dpllxarefdel() for multiple registrations
Currently, if there are multiple registrations of the same pin on the same dpll device, following warnings are observed: WARNING: CPU: 5 PID: 2212 at drivers/dpll/dpllcore.c:143 dpllxarefpindel.isra.0+0x21e/0x230 WARNING: CPU: 5 PID: 2212 at drivers/dpll/dpllcore.c:223 dpllpinunregister+0x2b3/0x2c0
The problem is, that in both dpllxarefdplldel() and dpllxarefpindel() registration is only removed from list in case the reference count drops to zero. That is wrong, the registration has to be removed always.
To fix this, remove the registration from the list and free it unconditionally, instead of doing it only when the ref reference counter reaches zero.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27027?
CVE-2024-27027 is categorized as a low severity vulnerability as it primarily involves warnings rather than exploitation risks.
How do I fix CVE-2024-27027?
To fix CVE-2024-27027, update your Linux kernel to one of the fixed versions provided such as 5.10.223-1 or 6.12.11-1.
What software is affected by CVE-2024-27027?
CVE-2024-27027 affects specific versions of the Linux kernel including 5.10.x, 6.1.x, and 6.12.x.
What issue does CVE-2024-27027 address?
CVE-2024-27027 addresses the improper handling of multiple registrations of the same pin on a DPLL device, resulting in warning messages.
Is exploitation possible with CVE-2024-27027?
Exploitation of CVE-2024-27027 is unlikely as it primarily generates warnings without leading to a security risk.