• 公告ID (KylinSec-SA-2024-2927)

摘要:

In the Linux kernel, the following vulnerability has been resolved:

phylib: fix potential use-after-free

Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call
to phy_device_reset(phydev) after the put_device() call in phy_detach().

The comment before the put_device() call says that the phydev might go
away with put_device().

Fix potential use-after-free by calling phy_device_reset() before
put_device().

安全等级: Low

公告ID: KylinSec-SA-2024-2927

发布日期: 2024年6月28日

关联CVE: CVE-2022-48754  

  • 详细介绍

1. 漏洞描述

   

In the Linux kernel, the following vulnerability has been resolved:

phylib: fix potential use-after-free

Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call
to phy_device_reset(phydev) after the put_device() call in phy_detach().

The comment before the put_device() call says that the phydev might go
away with put_device().

Fix potential use-after-free by calling phy_device_reset() before
put_device().

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2022-48754 KY3.4-5 kernel Unaffected
CVE-2022-48754 KY3.5.3 kernel Unaffected
CVE-2022-48754 V6 kernel Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-2926 下一篇:KylinSec-SA-2024-2928