Wind River Support Network

HomeDefectsLIN1023-7033
Fixed

LIN1023-7033 : Security Advisory - linux - CVE-2024-40903

Created: Jul 13, 2024    Updated: Jul 25, 2024
Resolved Date: Jul 14, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.12
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: tcpm: fix use-after-free case in tcpm_register_source_caps

There could be a potential use-after-free case in
tcpm_register_source_caps(). This could happen when:
 * new (say invalid) source caps are advertised
 * the existing source caps are unregistered
 * tcpm_register_source_caps() returns with an error as
   usb_power_delivery_register_capabilities() fails

This causes port->partner_source_caps to hold on to the now freed source
caps.

Reset port->partner_source_caps value to NULL after unregistering
existing source caps.

CREATE(Triage):(User=admin) CVE-2024-40903 (https://nvd.nist.gov/vuln/detail/CVE-2024-40903)

CVEs


Live chat
Online