CVE-2024-50166: fsl/fman: Fix refcount handling of fman-related devices
fsl/fman: Fix refcount handling of fman-related devices
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.25-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.64.2-1 - Upgrade
Upgrade
Linux kernel (fsl/fman)to a version that resolves this vulnerability.Patch Fix refcount handling of fman-related devices - Operational
Re-test fsl/fman mac_probe() and mac_remove() probe/remove paths after applying the fsl/fman refcount handling fix to ensure the previously leaking of_find_device_by_node() references are correctly released on error paths.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50166?
The severity of CVE-2024-50166 is classified as moderate due to potential impacts on refcount handling in the Linux kernel.
How do I fix CVE-2024-50166?
To fix CVE-2024-50166, update your Linux kernel to a version that includes the patch addressing this vulnerability.
What versions of the Linux kernel are affected by CVE-2024-50166?
CVE-2024-50166 affects Linux kernel versions from 4.5 to 6.6.59 and from 6.7 to 6.11.6, along with specific release candidates.
What are the potential consequences of not addressing CVE-2024-50166?
Not addressing CVE-2024-50166 may lead to stability issues or security risks related to incorrect reference counting in fman-related device handling.
Is CVE-2024-50166 a local or remote vulnerability?
CVE-2024-50166 is primarily a local vulnerability that could be exploited by an attacker with local access to the affected system.