Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: st: fix probed platform device ref count on probe error path The probe function never performs any paltform device allocation, thus error path "undo_platform_dev_alloc" is entirely bogus. It drops the reference count from the platform device being probed. If error path is triggered, this will lead to unbalanced device reference counts and premature release of device resources, thus possible use-after-free when releasing remaining devm-managed resources.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.18, < 4.19.321 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/060f41243ad7f6f5249fa7290dda0c01f723d12dPatch
- https://git.kernel.org/stable/c/1de989668708ce5875efc9d669d227212aeb9a90Patch
- https://git.kernel.org/stable/c/4c6735299540f3c82a5033d35be76a5c42e0fb18Patch
- https://git.kernel.org/stable/c/6aee4c5635d81f4809c3b9f0c198a65adfbb2adaPatch
- https://git.kernel.org/stable/c/b0979a885b9d4df2a25b88e9d444ccaa5f9f495cPatch
- https://git.kernel.org/stable/c/ddfcfeba891064b88bb844208b43bef2ef970f0cPatch
- https://git.kernel.org/stable/c/e1e5e8ea2731150d5ba7c707f9e02fafebcfeb49Patch
- https://git.kernel.org/stable/c/f3498650df0805c75b4e1c94d07423c46cbf4ce1Patch
- https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
FAQ
What is CVE-2024-46674?
CVE-2024-46674 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: st: fix probed platform device ref count on probe error path The probe function never performs any paltform device allo...
How severe is CVE-2024-46674?
CVE-2024-46674 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-46674?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.