Fixed                
                
            
            
                
                    Created: Apr 3, 2024   
                                            Updated: Feb 18, 2025                                    
                
                    
                                    
             
         
        
            
            
                                    
                        Resolved Date: Apr 19, 2024                    
                
                
                                    
                        Found In Version: 10.22.33.1                    
                
                                    
                        Fix Version: 10.22.33.16                    
                
                                        
                            Severity: Standard                        
                    
                                        
                            Applicable for: Wind River Linux LTS 22                        
                    
                                    
                        Component/s: Kernel                    
                
                
                             
         
                        
                In the Linux kernel, the following vulnerability has been resolved:
usb: roles: fix NULL pointer issue when put module's reference
In current design, usb role class driver will get usb_role_switch parent's
module reference after the user get usb_role_switch device and put the
reference after the user put the usb_role_switch device. However, the
parent device of usb_role_switch may be removed before the user put the
usb_role_switch. If so, then, NULL pointer issue will be met when the user
put the parent module's reference.
This will save the module pointer in structure of usb_role_switch. Then,
we don't need to find module by iterating long relations.
CREATE(Triage):(User=admin) CVE-2024-26747 (https://nvd.nist.gov/vuln/detail/CVE-2024-26747)