CVE-2024-49925: fbdev: efifb: Register sysfs groups through driver core
In the Linux kernel, the following vulnerability has been resolved:
fbdev: efifb: Register sysfs groups through driver core
The driver core can register and cleanup sysfs groups already. Make use of that functionality to simplify the error handling and cleanup.
Also avoid a UAF race during unregistering where the sysctl attributes were usable after the info struct was freed.
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49925?
The severity of CVE-2024-49925 is classified as moderate.
How do I fix CVE-2024-49925?
To fix CVE-2024-49925, update your Linux kernel to versions 6.6.55 or above, or apply patches provided by your Linux distribution.
What software is affected by CVE-2024-49925?
CVE-2024-49925 affects specific versions of the Linux kernel, including those between 6.7 and 6.10.14 and also 6.11.
Can CVE-2024-49925 lead to security risks?
Yes, CVE-2024-49925 can potentially lead to security risks such as unauthorized access if not addressed.
Is CVE-2024-49925 fixed in the latest Linux kernel?
Yes, CVE-2024-49925 has been fixed in the latest stable versions of the Linux kernel.