CVE-2024-58081: clk: mmp2: call pm_genpd_init() only after genpd.name is set

Published Mar 6, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

clk: mmp2: call pmgenpdinit() only after genpd.name is set

Setting the genpd's struct device's name with devsetname() is happening within pmgenpdinit(). If it remains NULL, things can blow up later, such as when crafting the devfs hierarchy for the power domain:

Unable to handle kernel NULL pointer dereference at virtual address 00000000 when read ... Call trace: strlen from startcreating+0x90/0x138 startcreating from debugfscreatedir+0x20/0x178 debugfscreatedir from genpddebugadd.part.0+0x4c/0x144 genpddebugadd.part.0 from genpddebuginit+0x74/0x90 genpddebuginit from dooneinitcall+0x5c/0x244 dooneinitcall from kernelinitfreeable+0x19c/0x1f4 kernelinitfreeable from kernelinit+0x1c/0x12c kernelinit from retfromfork+0x14/0x28

Bisecting tracks this crash back to commit 899f44531fe6 ("pmdomain: core: Add GENPDFLAGDEVNAMEFW flag"), which exchanges use of genpd->name with devname(&genpd->dev) in genpddebugadd.part().

Affected Software

4 affected componentsFixes available
Linux Linux kernel>=6.11.10<6.12.14
Linux Linux kernel>=6.13<6.13.3
Linux Kernel
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Mar 6, 2025
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 10, 2025
Data Sourced
via Ubuntu·05:18 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-58081?

CVE-2024-58081 has been classified with a medium severity level due to potential issues arising from improper initialization in the Linux kernel.

2

How do I fix CVE-2024-58081?

To fix CVE-2024-58081, ensure that the genpd's struct device's name is properly set before calling pm_genpd_init() in the Linux kernel.

3

What systems are affected by CVE-2024-58081?

CVE-2024-58081 affects versions of the Linux kernel that incorporate the affected clock management functionality.

4

What types of issues can arise if CVE-2024-58081 is not addressed?

If not addressed, CVE-2024-58081 can lead to instability in the system, including crashes or improper device management.

5

When was CVE-2024-58081 discovered?

CVE-2024-58081 was identified as a vulnerability in the Linux kernel's clock management functions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203