pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map()
Summary
| CVE | CVE-2024-36959 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-05-30 16:15:18 UTC |
| Updated | 2026-05-12 12:16:50 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() If we fail to allocate propname buffer, we need to drop the reference count we just took. Because the pinctrl_dt_free_maps() includes the droping operation, here we call it directly. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: NVD-CWE-Other
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected a988dcd3dd9e691c5ccc3324b209688f3b5453e9 06780473cb8a858d1d6cab2673e021b072a852d1 git | Not specified |
| CNA | Linux | Linux | affected 040f726fecd88121f3b95e70369785ad452dddf9 47d253c485491caaf70d8cd8c0248ae26e42581f git | Not specified |
| CNA | Linux | Linux | affected 777430aa4ddccaa5accec6db90ffc1d47f00d471 35ab679e8bb5a81a4f922d3efbd43e32bce69274 git | Not specified |
| CNA | Linux | Linux | affected 97e5b508e96176f1a73888ed89df396d7041bfcb 76aa2440deb9a35507590f2c981a69a57ecd305d git | Not specified |
| CNA | Linux | Linux | affected 91d5c5060ee24fe8da88cd585bb43b843d2f0dce 518d5ddafeb084d6d9b1773ed85164300037d0e6 git | Not specified |
| CNA | Linux | Linux | affected 91d5c5060ee24fe8da88cd585bb43b843d2f0dce 026e24cf31733dbd97f41cc9bc5273ace428eeec git | Not specified |
| CNA | Linux | Linux | affected 91d5c5060ee24fe8da88cd585bb43b843d2f0dce c7e02ccc9fdc496fe51e440e3e66ac36509ca049 git | Not specified |
| CNA | Linux | Linux | affected 91d5c5060ee24fe8da88cd585bb43b843d2f0dce a0cedbcc8852d6c77b00634b81e41f17f29d9404 git | Not specified |
| CNA | Linux | Linux | affected aaf552c5d53abe4659176e099575fe870d2e4768 git | Not specified |
| CNA | Linux | Linux | affected b4d9f55cd38435358bc16d580612bc0d798d7b4c git | Not specified |
| CNA | Linux | Linux | affected 5834a3a98cd266ad35a229923c0adbd0addc8d68 git | Not specified |
| CNA | Linux | Linux | affected 6.1 | Not specified |
| CNA | Linux | Linux | unaffected 6.1 semver | Not specified |
| CNA | Linux | Linux | unaffected 4.19.314 4.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.276 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.217 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.159 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.91 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.31 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.8.10 6.8.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.9 * original_commit_for_fix | Not specified |
| ADP | Siemens | RUGGEDCOM RST2428P | affected V3.1 custom | Not specified |
| ADP | Siemens | SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 Family | unaffected * custom | Not specified |
| ADP | Siemens | SCALANCE XCM-/XRM-/XCH-/XRH-300 Family | affected V3.1 custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 TM MFP - GNU/Linux Subsystem | affected * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/c7e02ccc9fdc496fe51e440e3e66ac36509ca049 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/47d253c485491caaf70d8cd8c0248ae26e42581f | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/518d5ddafeb084d6d9b1773ed85164300037d0e6 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| cert-portal.siemens.com/productcert/html/ssa-265688.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/a0cedbcc8852d6c77b00634b81e41f17f29d9404 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2024/06/msg00019.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List |
| cert-portal.siemens.com/productcert/html/ssa-613116.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/76aa2440deb9a35507590f2c981a69a57ecd305d | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/35ab679e8bb5a81a4f922d3efbd43e32bce69274 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2024/06/msg00020.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List |
| git.kernel.org/stable/c/06780473cb8a858d1d6cab2673e021b072a852d1 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/026e24cf31733dbd97f41cc9bc5273ace428eeec | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.