Junglewise Threat Intelligence

CVE-2024-36940: Linux Kernel double free in pinctrl_enable

CVE-2024-36940 · Severity: high · CVSS 7.8 · Published 2024-05-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's pin control (pinctrl) subsystem, which manages how hardware pins are configured on a system. An error in how the system handles memory cleanup can lead to a system crash or potentially allow an attacker to gain unauthorized control over the system. This issue primarily affects the stability and security of the operating system's core hardware management.

Technical details

A double-free vulnerability exists in drivers/pinctrl/core.c within the pinctrl_enable() function. The 'pctldev' structure is managed via the devm_ framework (allocated in devm_pinctrl_register_and_init), which automatically handles memory release through devm_pinctrl_dev_release(). However, pinctrl_enable() incorrectly attempted to manually kfree() this structure and destroy its associated mutex upon a failure to claim 'hogs'. A local attacker could potentially trigger this error path to cause memory corruption. The issue has been resolved by removing the redundant manual free and mutex destruction in the error path.

Affected products

  • Linux Linux Kernel 4.11 to 4.19.313, 4.20 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.158, 5.16 to 6.1.90, 6.2 to 6.6.30, 6.7 to 6.8.9

Timeline

  • 2024-03-21: other: Patch authored
  • 2024-05-17: patched: Patch committed to stable trees
  • 2024-05-30: disclosed: CVE published

References