{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-49986",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-10-21T12:17:06.054Z",
        "datePublished": "2024-10-21T18:02:30.507Z",
        "dateUpdated": "2026-08-05T11:40:54.750Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:40:54.750Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors\n\nx86_android_tablet_remove() frees the pdevs[] array, so it should not\nbe used after calling x86_android_tablet_remove().\n\nWhen platform_device_register() fails, store the pdevs[x] PTR_ERR() value\ninto the local ret variable before calling x86_android_tablet_remove()\nto avoid using pdevs[] after it has been freed."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable code is a platform driver `__init` probe routine reached only from `module_init()` on the local machine (boot-time DMI-modalias autoload or an explicit modprobe); there is no network, adjacent-network, or physical-interface path to it.\nAC:L - The defect fires unconditionally whenever `platform_device_register_full()` returns an error on affected hardware, and an attacker able to load/reload the module can retry the probe under heavy memory pressure or fault injection until an allocation in the registration path fails; no race needs to be won and no memory layout must be guessed.\nPR:L - On the affected tablets the module is autoloaded at boot via its DMI modalias, so the vulnerable path executes without the attacker holding any elevated capability, and the resulting dangling globals affect every local user of the system.\nUI:N - The probe path runs automatically during module init/boot; no victim has to open a file, mount a filesystem, or take any other action for the use-after-free to occur.\nS:U - The freed-memory access and the resulting double-free are confined to kernel slab memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a use-after-free read of freed slab memory whose contents an attacker can influence via heap grooming, and the false-success cascade leaves five dangling global pointers that are later dereferenced, giving a path to disclosing arbitrary reclaimed kernel data.\nI:H - When the freed slot reads back as zero the probe falsely reports success, so `x86_android_tablet_remove()` runs a second time and double-frees five allocations while unregistering devices from freed arrays — a double-free/UAF-write primitive that is the classic basis for slab corruption and control-flow hijack.\nA:H - The use-after-free read produces a KASAN report (a panic with `kasan.fault=panic`/`panic_on_warn`), and the downstream double-free and unregistration of stale device pointers reliably oops or panics the kernel."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/platform/x86/x86-android-tablets/core.c"
                    ],
                    "versions": [
                        {
                            "version": "5eba0141206ea521bbcfcf5067c174e825e943dd",
                            "lessThan": "ba0b09a2f327319e252d8f3032019b958c0a5cd9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5eba0141206ea521bbcfcf5067c174e825e943dd",
                            "lessThan": "aac871e493fc8809e60209d9899b1af07e9dbfc8",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5eba0141206ea521bbcfcf5067c174e825e943dd",
                            "lessThan": "f08adc5177bd4343df09033f62ab562c09ba7f7d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5eba0141206ea521bbcfcf5067c174e825e943dd",
                            "lessThan": "73a98cf79e4dbfa3d0c363e826c65aae089b313c",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5eba0141206ea521bbcfcf5067c174e825e943dd",
                            "lessThan": "2fae3129c0c08e72b1fe93e61fd8fd203252094a",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/platform/x86/x86-android-tablets/core.c"
                    ],
                    "versions": [
                        {
                            "version": "5.17",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.17",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.118",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.55",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.10.14",
                            "lessThanOrEqual": "6.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.11.3",
                            "lessThanOrEqual": "6.11.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.17",
                                    "versionEndExcluding": "6.1.118"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.17",
                                    "versionEndExcluding": "6.6.55"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.17",
                                    "versionEndExcluding": "6.10.14"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.17",
                                    "versionEndExcluding": "6.11.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.17",
                                    "versionEndExcluding": "6.12"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/ba0b09a2f327319e252d8f3032019b958c0a5cd9"
                },
                {
                    "url": "https://git.kernel.org/stable/c/aac871e493fc8809e60209d9899b1af07e9dbfc8"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f08adc5177bd4343df09033f62ab562c09ba7f7d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/73a98cf79e4dbfa3d0c363e826c65aae089b313c"
                },
                {
                    "url": "https://git.kernel.org/stable/c/2fae3129c0c08e72b1fe93e61fd8fd203252094a"
                }
            ],
            "title": "platform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2024-49986",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2024-10-22T13:31:52.405386Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-10-22T13:38:43.597Z"
                }
            },
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-03T22:24:08.353Z"
                }
            }
        ]
    }
}