{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-58003",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-02-27T02:10:48.226Z",
        "datePublished": "2025-02-27T02:12:00.834Z",
        "dateUpdated": "2026-08-05T11:47:21.273Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:47:21.273Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: i2c: ds90ub9x3: Fix extra fwnode_handle_put()\n\nThe ub913 and ub953 drivers call fwnode_handle_put(priv->sd.fwnode) as\npart of their remove process, and if the driver is removed multiple\ntimes, eventually leads to put \"overflow\", possibly causing memory\ncorruption or crash.\n\nThe fwnode_handle_put() is a leftover from commit 905f88ccebb1 (\"media:\ni2c: ds90ub9x3: Fix sub-device matching\"), which changed the code\nrelated to the sd.fwnode, but missed removing these fwnode_handle_put()\ncalls."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable teardown path is reached only through local driver lifecycle operations — sysfs bind/unbind of the ds90ub913a/ds90ub953 i2c driver or module unload/reload. There is no network, adjacent-network, or physical-hotplug path to the FPD-Link serializer i2c device, which is statically instantiated by the ds90ub960 deserializer at its probe.\nAC:L - Each unbind/rebind cycle deterministically drops exactly one unowned reference on the serializer fwnode, so the attacker simply repeats the cycle 3-4 times until the refcount underflows; no race, timing window, or uncontrollable memory-layout condition is involved. Heap grooming of the freed device_node is likewise under attacker control between cycles.\nPR:L - Consistent with this repo's treatment of driver unbind/module-reload lifetime bugs, an unprivileged local user with access to the driver model is scored as low privileges rather than full administrative privilege. The attacker needs no capability specific to the media subsystem and no authentication beyond local account access.\nUI:N - The attacker performs the repeated unbind/bind operations themselves; no victim action, filesystem mount, or file open is required. The refcount underflow accumulates purely from attacker-initiated driver removals.\nS:U - The underflowed fwnode and the resulting use-after-free are both within the kernel's own security authority; there is no VM, IOMMU, or sandbox boundary crossed. This is a standard in-kernel memory-safety issue affecting the same security scope.\nC:H - The premature free of the device_node/fwnode leaves stale pointers in the i2c client device and in ds90ub960's rxport->ser.fwnode, so subsequent fwnode property reads operate on reallocated attacker-groomed heap memory, enabling disclosure of arbitrary kernel data. Reference-count underflow leading to use-after-free is scored High per kernel guidance.\nI:H - struct fwnode_handle carries a const struct fwnode_operations *ops that every fwnode_call_*_op macro invokes indirectly, so a freed-and-resprayed node hands the attacker a controlled indirect-call primitive and thus control-flow hijacking. The commit message itself warns of \"memory corruption.\"\nA:H - Even on static device trees where the node is not actually freed, of_node_release() emits an error plus dump_stack() and the following put produces a \"refcount_t: underflow; use-after-free\" kobject WARN — an oops, and a full panic under panic_on_warn. On dynamic/overlay nodes the use-after-free crashes the kernel outright."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/media/i2c/ds90ub913.c",
                        "drivers/media/i2c/ds90ub953.c"
                    ],
                    "versions": [
                        {
                            "version": "905f88ccebb14e42bcd19455b0d9c0d4808f1897",
                            "lessThan": "474d7baf91d37bc411fa60de5bbf03c9dd82e18a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "905f88ccebb14e42bcd19455b0d9c0d4808f1897",
                            "lessThan": "f4e4373322f8d4c19721831f7fb989e52d30dab0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "905f88ccebb14e42bcd19455b0d9c0d4808f1897",
                            "lessThan": "70743d6a8b256225675711e7983825f1be86062d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "905f88ccebb14e42bcd19455b0d9c0d4808f1897",
                            "lessThan": "60b45ece41c5632a3a3274115a401cb244180646",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/media/i2c/ds90ub913.c",
                        "drivers/media/i2c/ds90ub953.c"
                    ],
                    "versions": [
                        {
                            "version": "6.6",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.6",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.78",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.14",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.13.3",
                            "lessThanOrEqual": "6.13.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.14",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.6",
                                    "versionEndExcluding": "6.6.78"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.6",
                                    "versionEndExcluding": "6.12.14"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.6",
                                    "versionEndExcluding": "6.13.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.6",
                                    "versionEndExcluding": "6.14"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/474d7baf91d37bc411fa60de5bbf03c9dd82e18a"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f4e4373322f8d4c19721831f7fb989e52d30dab0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/70743d6a8b256225675711e7983825f1be86062d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/60b45ece41c5632a3a3274115a401cb244180646"
                }
            ],
            "title": "media: i2c: ds90ub9x3: Fix extra fwnode_handle_put()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}