Executive brief
A vulnerability in the Linux kernel's battery management system could allow a local user to cause a system crash. The issue occurs when the system incorrectly handles battery hardware extensions, leading to a kernel panic during certain hardware events or driver unloads. This primarily impacts system availability and could be used to disrupt operations on affected Linux devices.
Technical details
A vulnerability exists in the Linux kernel ACPI battery driver (drivers/acpi/battery.c) classified as a 'use-after-free' or 'operation on a resource after release' (CWE-672). When a battery hook returns an error during the addition of a new battery, the kernel automatically unregisters it. However, the hook provider, unaware of this automatic action, may subsequently call battery_hook_unregister(), leading to a kernel crash. The fix involves using list_del_init() and checking if the list is empty before unregistering to ensure the hook is not processed twice. This is a local attack vector requiring low privileges and results in a denial of service (system crash).
Affected products
- Linux Linux Kernel 4.17 to 5.10.226, 5.11 to 5.15.167, 5.16 to 6.1.112, 6.2 to 6.6.54, 6.7 to 6.10.13, 6.11 to 6.11.2
Timeline
- 2024-10-01: patched: Initial patch submitted by Armin Wolf
- 2024-10-21: disclosed: CVE-2024-49955 published
References
- https://git.kernel.org/stable/c/07b98400cb0285a6348188aa8c5ec6a2ae0551f7
- https://git.kernel.org/stable/c/76959aff14a0012ad6b984ec7686d163deccdc16
- https://git.kernel.org/stable/c/76fb2cbf01571926da8ecf6876cc8cb07d3f5183
- https://git.kernel.org/stable/c/9f469ef1c79dac7f9ac1518643a33703918f7e13
- https://git.kernel.org/stable/c/c47843a831e0eae007ad7e848d208e675ba4c132
- https://git.kernel.org/stable/c/ca1fb7942a287b40659cc79551a1de54a2c2e7d5
- https://git.kernel.org/stable/c/ca26e8eed9c1c6651f51f7fa38fe444f8573cd1b