Bug 1227825 (CVE-2024-40991) - VUL-0: CVE-2024-40991: kernel: dmaengine: ti: k3-udma-glue: Fix of_k3_udma_glue_parse_chn_by_id()
Summary: VUL-0: CVE-2024-40991: kernel: dmaengine: ti: k3-udma-glue: Fix of_k3_udma_gl...
Status: RESOLVED FIXED
Alias: CVE-2024-40991
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Kernel Bugs
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/413918/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-15 13:33 UTC by SMASH SMASH
Modified: 2024-07-17 08:52 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-07-15 13:33:42 UTC
In the Linux kernel, the following vulnerability has been resolved:

dmaengine: ti: k3-udma-glue: Fix of_k3_udma_glue_parse_chn_by_id()

The of_k3_udma_glue_parse_chn_by_id() helper function erroneously
invokes "of_node_put()" on the "udmax_np" device-node passed to it,
without having incremented its reference count at any point. Fix it.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-40991
https://www.cve.org/CVERecord?id=CVE-2024-40991
https://git.kernel.org/stable/c/a5ab5f413d1e4c7ed5f64271b025f0726374509e
https://git.kernel.org/stable/c/ba27e9d2207784da748b19170a2e56bd7770bd81
https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-40991.mbox