CVE-2024-56575: media: imx-jpeg: Ensure power suppliers be suspended before detach them
In the Linux kernel, the following vulnerability has been resolved:
media: imx-jpeg: Ensure power suppliers be suspended before detach them
The power suppliers are always requested to suspend asynchronously, devpmdomaindetach() requires the caller to ensure proper synchronization of this function with power management callbacks. otherwise the detach may led to kernel panic, like below:
[ 1457.107934] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000040 [ 1457.116777] Mem abort info: [ 1457.119589] ESR = 0x0000000096000004 [ 1457.123358] EC = 0x25: DABT (current EL), IL = 32 bits [ 1457.128692] SET = 0, FnV = 0 [ 1457.131764] EA = 0, S1PTW = 0 [ 1457.134920] FSC = 0x04: level 0 translation fault [ 1457.139812] Data abort info: [ 1457.142707] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 1457.148196] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 1457.153256] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 1457.158563] user pgtable: 4k pages, 48-bit VAs, pgdp=00000001138b6000 [ 1457.165000] [0000000000000040] pgd=0000000000000000, p4d=0000000000000000 [ 1457.171792] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP [ 1457.178045] Modules linked in: v4l2jpeg wave6vpuctrl(-) [last unloaded: mxcjpegencdec] [ 1457.186383] CPU: 0 PID: 51938 Comm: kworker/0:3 Not tainted 6.6.36-gd23d64eea511 #66 [ 1457.194112] Hardware name: NXP i.MX95 19X19 board (DT) [ 1457.199236] Workqueue: pm pmruntimework [ 1457.203247] pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 1457.210188] pc : genpdruntimesuspend+0x20/0x290 [ 1457.214886] lr : rpmcallback+0x48/0x1d8 [ 1457.218968] sp : ffff80008250bc50 [ 1457.222270] x29: ffff80008250bc50 x28: 0000000000000000 x27: 0000000000000000 [ 1457.229394] x26: 0000000000000000 x25: 0000000000000008 x24: 00000000000f4240 [ 1457.236518] x23: 0000000000000000 x22: ffff00008590f0e4 x21: 0000000000000008 [ 1457.243642] x20: ffff80008099c434 x19: ffff00008590f000 x18: ffffffffffffffff [ 1457.250766] x17: 5300326563697665 x16: 645f676e696c6f6f x15: 63343a6d726f6674 [ 1457.257890] x14: 0000000000000004 x13: 00000000000003a4 x12: 0000000000000002 [ 1457.265014] x11: 0000000000000000 x10: 0000000000000a60 x9 : ffff80008250bbb0 [ 1457.272138] x8 : ffff000092937200 x7 : ffff0003fdf6af80 x6 : 0000000000000000 [ 1457.279262] x5 : 00000000410fd050 x4 : 0000000000200000 x3 : 0000000000000000 [ 1457.286386] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff00008590f000 [ 1457.293510] Call trace: [ 1457.295946] genpdruntimesuspend+0x20/0x290 [ 1457.300296] rpmcallback+0x48/0x1d8 [ 1457.304038] rpmcallback+0x6c/0x78 [ 1457.307515] rpmsuspend+0x10c/0x570 [ 1457.311077] pmruntimework+0xc4/0xc8 [ 1457.314813] processonework+0x138/0x248 [ 1457.318816] workerthread+0x320/0x438 [ 1457.322552] kthread+0x110/0x114 [ 1457.325767] retfromfork+0x10/0x20
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56575?
CVE-2024-56575 has been classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2024-56575?
To fix CVE-2024-56575, ensure that you update your Linux kernel to a version that is patched against this vulnerability.
Which versions of the Linux kernel are affected by CVE-2024-56575?
CVE-2024-56575 affects Linux kernel versions from 5.13 to 5.15.174 and 5.16 to 6.1.120, as well as versions from 6.2 to 6.6.64 and from 6.7 to 6.12.4.
What should I do if my system is vulnerable to CVE-2024-56575?
If your system is vulnerable to CVE-2024-56575, you should prioritize upgrading to the latest secure version of the Linux kernel.
Is CVE-2024-56575 a remote or local vulnerability?
CVE-2024-56575 is considered a local vulnerability, requiring local user access to exploit.