CVE-2024-57979: pps: Fix a use-after-free

Published Feb 27, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

pps: Fix a use-after-free

On a board running ntpd and gpsd, I'm seeing a consistent use-after-free in sysexit() from gpsd when rebooting:

pps pps1: removed ------------[ cut here ]------------ kobject: '(null)' (00000000db4bec24): is not initialized, yet kobjectput() is being called. WARNING: CPU: 2 PID: 440 at lib/kobject.c:734 kobjectput+0x120/0x150 CPU: 2 UID: 299 PID: 440 Comm: gpsd Not tainted 6.11.0-rc6-00308-gb31c44928842 #1 Hardware name: Raspberry Pi 4 Model B Rev 1.1 (DT) pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : kobjectput+0x120/0x150 lr : kobjectput+0x120/0x150 sp : ffffffc0803d3ae0 x29: ffffffc0803d3ae0 x28: ffffff8042dc9738 x27: 0000000000000001 x26: 0000000000000000 x25: ffffff8042dc9040 x24: ffffff8042dc9440 x23: ffffff80402a4620 x22: ffffff8042ef4bd0 x21: ffffff80405cb600 x20: 000000000008001b x19: ffffff8040b3b6e0 x18: 0000000000000000 x17: 0000000000000000 x16: 0000000000000000 x15: 696e6920746f6e20 x14: 7369203a29343263 x13: 205d303434542020 x12: 0000000000000000 x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000 x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000 x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000 x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000 Call trace: kobjectput+0x120/0x150 cdevput+0x20/0x3c fput+0x2c4/0x2d8 fput+0x1c/0x38 taskworkrun+0x70/0xfc doexit+0x2a0/0x924 dogroupexit+0x34/0x90 getsignal+0x7fc/0x8c0 dosignal+0x128/0x13b4 donotifyresume+0xdc/0x160 el0svc+0xd4/0xf8 el0t64synchandler+0x140/0x14c el0t64sync+0x190/0x194 ---[ end trace 0000000000000000 ]---

...followed by more symptoms of corruption, with similar stacks:

refcountt: underflow; use-after-free. kernel BUG at lib/listdebug.c:62! Kernel panic - not syncing: Oops - BUG: Fatal exception

This happens because ppsdevicedestruct() frees the ppsdevice with the embedded cdev immediately after calling cdevdel(), but, as the comment above cdevdel() notes, fops for previously opened cdevs are still callable even after cdevdel() returns. I think this bug has always been there: I can't explain why it suddenly started happening every time I reboot this particular board.

In commit d953e0e837e6 ("pps: Fix a use-after free bug when unregistering a source."), George Spelvin suggested removing the embedded cdev. That seems like the simplest way to fix this, so I've implemented his suggestion, using registerchrdev() with ppsidr becoming the source of truth for which minor corresponds to which device.

But now that ppsidr defines userspace visibility instead of cdevadd(), we need to be sure the pps->dev refcount can't reach zero while userspace can still find it again. So, the idrremove() call moves to ppsunregistercdev(), and ppsidr now holds a reference to pps->dev.

ppscore: source serial1 got cdev (251:1) <...> pps pps1: removed ppscore: unregistering pps1 ppscore: deallocating pps1

Affected Software

12 affected componentsFixes available
Linux Kernel
Linux Linux kernel>=3.2.40<3.3
Linux Linux kernel>=3.4.87<3.5
Linux Linux kernel>=3.8.1<5.4.291
Linux Linux kernel>=5.5<5.10.235
Linux Linux kernel>=5.11<5.15.179
Linux Linux kernel>=5.16<6.1.129
Linux Linux kernel>=6.2<6.6.76
Linux Linux kernel>=6.7<6.12.13
Linux Linux kernel>=6.13<6.13.2
Microsoft cbl2 kernel 5.15.176.3-3<5.15.180.1-1
5.15.180.1-1
Microsoft cbl2 kernel 5.15.180.1-1<5.15.180.1-1
5.15.180.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 5.15.180.1-1
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch d953e0e837e6
  3. Configuration

    Update the pps subsystem teardown logic so idr_remove() placement prevents pps_device_destruct() freeing pps_device while pps_idr still holds a reference (per commit discussion: move idr_remove() after ensuring the pps->dev refcount cannot reach zero).

    Kernel pps device handling pss_device_destruct()/idr_remove ordering (userspace visibility model vs cdev_add) = Ensure idr_remove() is moved to the correct location so pps_idr does not hold a ref that can reach zero during teardown

Event History

Feb 27, 2025
CVE Published
via MITRE·02:07 AM
Data Sourced
via MITRE·02:07 AM
DescriptionSeverity
Data Sourced
via NVD·02:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·03:03 AM
DescriptionSeverityAffected Software
May 5, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Updated
via Microsoft·07:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2024-57979?

CVE-2024-57979 is classified as a high severity vulnerability due to its potential to cause a use-after-free condition in the Linux kernel.

2

How do I fix CVE-2024-57979?

To fix CVE-2024-57979, ensure that you update your Linux kernel to the latest version that contains the patch addressing this vulnerability.

3

Which versions of the Linux kernel are affected by CVE-2024-57979?

Specific versions of the Linux kernel prior to the latest updates may be affected, so checking the release notes for your kernel version is recommended.

4

What impact does CVE-2024-57979 have on my system?

CVE-2024-57979 may lead to system instability or crashes due to the use-after-free issue during operations involving ntpd and gpsd.

5

Is CVE-2024-57979 exploitable remotely?

CVE-2024-57979 could potentially be exploited remotely if certain conditions are met, making it essential to apply patches promptly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203