{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-57984",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-02-27T02:04:28.913Z",
        "datePublished": "2025-02-27T02:07:09.373Z",
        "dateUpdated": "2026-08-05T11:47:10.554Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:47:10.554Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition\n\nIn dw_i3c_common_probe, &master->hj_work is bound with\ndw_i3c_hj_work. And dw_i3c_master_irq_handler can call\ndw_i3c_master_irq_handle_ibis function to start the work.\n\nIf we remove the module which will call dw_i3c_common_remove to\nmake cleanup, it will free master->base through i3c_master_unregister\nwhile the work mentioned above will be used. The sequence of operations\nthat may lead to a UAF bug is as follows:\n\nCPU0                                      CPU1\n\n                                     | dw_i3c_hj_work\ndw_i3c_common_remove                 |\ni3c_master_unregister(&master->base) |\ndevice_unregister(&master->dev)      |\ndevice_release                       |\n//free master->base                  |\n                                     | i3c_master_do_daa(&master->base)\n                                     | //use master->base\n\nFix it by ensuring that the work is canceled before proceeding with\nthe cleanup in dw_i3c_common_remove."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The attacker-controlled side of the race is driver teardown, reached locally via module unload or a write to the platform driver's sysfs unbind attribute, and the hot-join IBI side originates on the on-board I3C bus. No network or remote protocol path reaches this code, so the entry point is local system access.\nAC:L - The attacker directly controls the teardown side of the race and can repeat bind/unbind cycles indefinitely until the pending hj_work collides with i3c_master_unregister(), so success does not depend on conditions outside their influence. Hot-Join IBIs recur on any bus where hot-join is enabled, giving the attacker repeated windows.\nPR:L - A basic local account is sufficient to reach the i3c sysfs surface and drive the device teardown/re-probe cycling that opens the race window, and no capability check gates the vulnerable hj_work path itself. Consistent with the scoring of equivalent driver remove-path work-item UAFs, low privileges are the defensible assumption.\nUI:N - The attacker performs the removal and the Hot-Join IBI is delivered by hardware on the bus; no victim action, mount, or file open is required. Exploitation completes entirely from the attacker's own operations.\nS:U - The use-after-free corrupts kernel heap state within the same kernel security authority, with no crossing of a VM, IOMMU, or sandbox boundary. Impact is confined to the kernel that owns the vulnerable driver.\nC:H - The freed dw_i3c_master object is read back by i3c_master_do_daa(), including its ops pointer and device table, so an attacker who reclaims the allocation gains control over interpreted kernel memory and can leverage it for arbitrary kernel memory disclosure. Per use-after-free scoring guidance this is High.\nI:H - i3c_master_do_daa() calls master->ops->do_daa(master) — an indirect branch through a function pointer read from freed memory — and i3c_master_register_new_i3c_devs() then mutates torn-down bus lists, providing both control-flow hijack and write primitives after heap spraying. This is full integrity compromise.\nA:H - Even without successful exploitation the work dereferences freed memory and performs readl/writel against MMIO already unmapped by devres, producing a kernel oops or panic. Any use-after-free of this kind is a reliable crash."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/i3c/master/dw-i3c-master.c"
                    ],
                    "versions": [
                        {
                            "version": "1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef",
                            "lessThan": "60d2fb033a999bb644f8e8606ff4a1b82de36c6f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef",
                            "lessThan": "9b0063098fcde17cd2894f2c96459b23388507ca",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef",
                            "lessThan": "fc84dd3c909a372c0d130f5f84c404717c17eed8",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef",
                            "lessThan": "b75439c945b94dd8a2b645355bdb56f948052601",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/i3c/master/dw-i3c-master.c"
                    ],
                    "versions": [
                        {
                            "version": "5.0",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.0",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.76",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.13",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.13.2",
                            "lessThanOrEqual": "6.13.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.14",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.0",
                                    "versionEndExcluding": "6.6.76"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.0",
                                    "versionEndExcluding": "6.12.13"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.0",
                                    "versionEndExcluding": "6.13.2"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.0",
                                    "versionEndExcluding": "6.14"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/60d2fb033a999bb644f8e8606ff4a1b82de36c6f"
                },
                {
                    "url": "https://git.kernel.org/stable/c/9b0063098fcde17cd2894f2c96459b23388507ca"
                },
                {
                    "url": "https://git.kernel.org/stable/c/fc84dd3c909a372c0d130f5f84c404717c17eed8"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b75439c945b94dd8a2b645355bdb56f948052601"
                }
            ],
            "title": "i3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 7.8,
                            "attackVector": "LOCAL",
                            "baseSeverity": "HIGH",
                            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                            "integrityImpact": "HIGH",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "LOW",
                            "confidentialityImpact": "HIGH"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2024-57984",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2025-02-27T17:58:19.220421Z"
                            }
                        }
                    }
                ],
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "lang": "en",
                                "type": "CWE",
                                "cweId": "CWE-416",
                                "description": "CWE-416 Use After Free"
                            }
                        ]
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-02-27T18:02:28.323Z"
                }
            }
        ]
    }
}