U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-27027

Change History

New CVE Received by NIST 5/01/2024 9:15:48 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

dpll: fix dpll_xa_ref_*_del() for multiple registrations

Currently, if there are multiple registrations of the same pin on the
same dpll device, following warnings are observed:
WARNING: CPU: 5 PID: 2212 at drivers/dpll/dpll_core.c:143 dpll_xa_ref_pin_del.isra.0+0x21e/0x230
WARNING: CPU: 5 PID: 2212 at drivers/dpll/dpll_core.c:223 __dpll_pin_unregister+0x2b3/0x2c0

The problem is, that in both dpll_xa_ref_dpll_del() and
dpll_xa_ref_pin_del() registration is only removed from list in case the
reference count drops to zero. That is wrong, the registration has to
be removed always.

To fix this, remove the registration from the list and free
it unconditionally, instead of doing it only when the ref reference
counter reaches zero.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/769324eb35143462542cdb15483cdaf4877bf661 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/b27e32e9367dac024cd6f61f22655714f483fd67 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/b446631f355ece73b13c311dd712c47381a23172 [No types assigned]