U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-49981

Change History

New CVE Received from kernel.org 10/21/2024 2:15:18 PM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

media: venus: fix use after free bug in venus_remove due to race condition

in venus_probe, core->work is bound with venus_sys_error_handler, which is
used to handle error. The code use core->sys_err_done to make sync work.
The core->work is started in venus_event_notify.

If we call venus_remove, there might be an unfished work. The possible
sequence is as follows:

CPU0                  CPU1

                     |venus_sys_error_handler
venus_remove         |
hfi_destroy	 		 |
venus_hfi_destroy	 |
kfree(hdev);	     |
                     |hfi_reinit
					 |venus_hfi_queues_reinit
                     |//use hdev

Fix it by canceling the work in venus_remove.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/10941d4f99a5a34999121b314afcd9c0a1c14f15 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/2a541fcc0bd2b05a458e9613376df1289ec11621 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/60b6968341a6dd5353554f3e72db554693a128a5 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/b0686aedc5f1343442d044bd64eeac7e7a391f4e [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/bf6be32e2d39f6301ff1831e249d32a8744ab28a [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/c5a85ed88e043474161bbfe54002c89c1cb50ee2 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/d925e9f7fb5a2dbefd1a73fc01061f38c7becd4c [No types assigned]