PCI/ASPM: Fix link state exit during switch upstream function removal
Summary
| CVE | CVE-2024-58093 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-04-16 15:15:53 UTC |
| Updated | 2026-07-16 12:16:43 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstream function removal Before 456d8aa37d0f ("PCI/ASPM: Disable ASPM on MFD function removal to avoid use-after-free"), we would free the ASPM link only after the last function on the bus pertaining to the given link was removed. That was too late. If function 0 is removed before sibling function, link->downstream would point to free'd memory after. After above change, we freed the ASPM parent link state upon any function removal on the bus pertaining to a given link. That is too early. If the link is to a PCIe switch with MFD on the upstream port, then removing functions other than 0 first would free a link which still remains parent_link to the remaining downstream ports. The resulting GPFs are especially frequent during hot-unplug, because pciehp removes devices on the link bus in reverse order. On that switch, function 0 is the virtual P2P bridge to the internal bus. Free exactly when function 0 is removed -- before the parent link is obsolete, but after all subordinate links are gone. [kwilczynski: commit log] |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-416
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 666e7f9d60cee23077ea3e6331f6f8a19f7ea03f 0a0f9aecf66b98959aab7fb5764b4b3e522f4f5b git | Not specified |
| CNA | Linux | Linux | affected 7badf4d6f49a358a01ab072bbff88d3ee886c33b 62db339ecc3d58d8fd83a9e4d80061cd943bb6e2 git | Not specified |
| CNA | Linux | Linux | affected 9856c0de49052174ab474113f4ba40c02aaee086 e5cd58f61e9d8024ee11bd78c12c8916891d4077 git | Not specified |
| CNA | Linux | Linux | affected 7aecdd47910c51707696e8b0e045b9f88bd4230f cd4b07507794f7ad1a74e12eca75121d98187e66 git | Not specified |
| CNA | Linux | Linux | affected 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 8b930ddc2044e36866c41423e89889e0258695a3 git | Not specified |
| CNA | Linux | Linux | affected 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 f556b6ba0ac5f8353287ce6ed761228f0b4fafb7 git | Not specified |
| CNA | Linux | Linux | affected 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 ba4cdc14c0d4df00d3e99bff7fe545303db98183 git | Not specified |
| CNA | Linux | Linux | affected 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 4d96930239981f312821a4065db8cc0f8240a173 git | Not specified |
| CNA | Linux | Linux | affected 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 cbf937dcadfd571a434f8074d057b32cd14fbea5 git | Not specified |
| CNA | Linux | Linux | affected d51d2eeae4ce54d542909c4d9d07bf371a78592c git | Not specified |
| CNA | Linux | Linux | affected 4203722d51afe3d239e03f15cc73efdf023a7103 git | Not specified |
| CNA | Linux | Linux | affected 5.4.251 5.4.292 semver | Not specified |
| CNA | Linux | Linux | affected 5.10.188 5.10.236 semver | Not specified |
| CNA | Linux | Linux | affected 5.15.121 5.15.180 semver | Not specified |
| CNA | Linux | Linux | affected 6.1.39 6.1.134 semver | Not specified |
| CNA | Linux | Linux | affected 6.3.13 6.4 semver | Not specified |
| CNA | Linux | Linux | affected 6.4.4 6.5 semver | Not specified |
| CNA | Linux | Linux | affected 6.5 | Not specified |
| CNA | Linux | Linux | unaffected 6.5 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.292 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.236 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.180 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.134 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.87 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.23 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.13.11 6.13.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.14.2 6.14.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.15 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/f556b6ba0ac5f8353287ce6ed761228f0b4fafb7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/0a0f9aecf66b98959aab7fb5764b4b3e522f4f5b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/62db339ecc3d58d8fd83a9e4d80061cd943bb6e2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/cbf937dcadfd571a434f8074d057b32cd14fbea5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/8b930ddc2044e36866c41423e89889e0258695a3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4d96930239981f312821a4065db8cc0f8240a173 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/cd4b07507794f7ad1a74e12eca75121d98187e66 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ba4cdc14c0d4df00d3e99bff7fe545303db98183 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e5cd58f61e9d8024ee11bd78c12c8916891d4077 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.