CVE-2024-43830: leds: trigger: Unregister sysfs attributes before calling deactivate()

Published Aug 17, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

leds: trigger: Unregister sysfs attributes before calling deactivate()

Triggers which have trigger specific sysfs attributes typically store related data in trigger-data allocated by the activate() callback and freed by the deactivate() callback.

Calling deviceremovegroups() after calling deactivate() leaves a window where the sysfs attributes show/store functions could be called after deactivation and then operate on the just freed trigger-data.

Move the deviceremovegroups() call to before deactivate() to close this race window.

This also makes the deactivation path properly do things in reverse order of the activation path which calls the activate() callback before calling deviceaddgroups().

Affected Software

9 affected componentsFixes available
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Linux Linux kernel>=4.19<4.19.320
Linux Linux kernel>=4.20<5.4.282
Linux Linux kernel>=5.5<5.10.224
Linux Linux kernel>=5.11<5.15.165
Linux Linux kernel>=5.16<6.1.103
Linux Linux kernel>=6.2<6.6.44
Linux Linux kernel>=6.7<6.10.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
  2. Upgrade

    Upgrade debian/linux-6.1 to a version that resolves this vulnerability.

    Fixed in 6.1.129-1~deb11u1
  3. Configuration

    In the leds trigger deactivation path, call device_remove_groups() before calling the trigger's deactivate() callback so sysfs show/store cannot run after trigger-data is freed by deactivate().

    Linux kernel (leds: trigger) deactivation order (device_remove_groups vs deactivate) = Move device_remove_groups() call to before deactivate()

Event History

Aug 17, 2024
CVE Published
via MITRE·09:21 AM
Data Sourced
via MITRE·09:21 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 AM
Description
Data Sourced
via NVD·10:15 AM
RemedySeverityWeaknessAffected Software
May 9, 2025
Data Sourced
via Ubuntu·12:36 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-43830?

CVE-2024-43830 is considered a vulnerability in the Linux kernel related to improper handling of sysfs attributes.

2

How do I fix CVE-2024-43830?

To fix CVE-2024-43830, update to the patched versions of the Linux kernel as specified in the advisory.

3

What are the affected versions of Linux for CVE-2024-43830?

CVE-2024-43830 affects Linux kernel versions up to 5.10.223-1 and specific 6.1 versions prior to their patched releases.

4

What impact does CVE-2024-43830 have on system security?

CVE-2024-43830 may lead to potential exploitation due to improper attribute deactivation in Linux kernel triggers.

5

Is CVE-2024-43830 specific to a certain Linux distribution?

CVE-2024-43830 primarily affects Debian-based distributions that utilize the specified Linux kernel versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203