{"id":"DEBIAN-CVE-2024-47688","details":"In the Linux kernel, the following vulnerability has been resolved:  driver core: Fix a potential null-ptr-deref in module_add_driver()  Inject fault while probing of-fpga-region, if kasprintf() fails in module_add_driver(), the second sysfs_remove_link() in exit path will cause null-ptr-deref as below because kernfs_name_hash() will call strlen() with NULL driver_name.  Fix it by releasing resources based on the exit path sequence.  \t KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] \t Mem abort info: \t   ESR = 0x0000000096000005 \t   EC = 0x25: DABT (current EL), IL = 32 bits \t   SET = 0, FnV = 0 \t   EA = 0, S1PTW = 0 \t   FSC = 0x05: level 1 translation fault \t Data abort info: \t   ISV = 0, ISS = 0x00000005, ISS2 = 0x00000000 \t   CM = 0, WnR = 0, TnD = 0, TagAccess = 0 \t   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 \t [dfffffc000000000] address between user and kernel address ranges \t Internal error: Oops: 0000000096000005 [#1] PREEMPT SMP \t Dumping ftrace buffer: \t    (ftrace buffer empty) \t Modules linked in: of_fpga_region(+) fpga_region fpga_bridge cfg80211 rfkill 8021q garp mrp stp llc ipv6 [last unloaded: of_fpga_region] \t CPU: 2 UID: 0 PID: 2036 Comm: modprobe Not tainted 6.11.0-rc2-g6a0e38264012 #295 \t Hardware name: linux,dummy-virt (DT) \t pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) \t pc : strlen+0x24/0xb0 \t lr : kernfs_name_hash+0x1c/0xc4 \t sp : ffffffc081f97380 \t x29: ffffffc081f97380 x28: ffffffc081f97b90 x27: ffffff80c821c2a0 \t x26: ffffffedac0be418 x25: 0000000000000000 x24: ffffff80c09d2000 \t x23: 0000000000000000 x22: 0000000000000000 x21: 0000000000000000 \t x20: 0000000000000000 x19: 0000000000000000 x18: 0000000000001840 \t x17: 0000000000000000 x16: 0000000000000000 x15: 1ffffff8103f2e42 \t x14: 00000000f1f1f1f1 x13: 0000000000000004 x12: ffffffb01812d61d \t x11: 1ffffff01812d61c x10: ffffffb01812d61c x9 : dfffffc000000000 \t x8 : 0000004fe7ed29e4 x7 : ffffff80c096b0e7 x6 : 0000000000000001 \t x5 : ffffff80c096b0e0 x4 : 1ffffffdb990efa2 x3 : 0000000000000000 \t x2 : 0000000000000000 x1 : dfffffc000000000 x0 : 0000000000000000 \t Call trace: \t  strlen+0x24/0xb0 \t  kernfs_name_hash+0x1c/0xc4 \t  kernfs_find_ns+0x118/0x2e8 \t  kernfs_remove_by_name_ns+0x80/0x100 \t  sysfs_remove_link+0x74/0xa8 \t  module_add_driver+0x278/0x394 \t  bus_add_driver+0x1f0/0x43c \t  driver_register+0xf4/0x3c0 \t  __platform_driver_register+0x60/0x88 \t  of_fpga_region_init+0x20/0x1000 [of_fpga_region] \t  do_one_initcall+0x110/0x788 \t  do_init_module+0x1dc/0x5c8 \t  load_module+0x3c38/0x4cac \t  init_module_from_file+0xd4/0x128 \t  idempotent_init_module+0x2cc/0x528 \t  __arm64_sys_finit_module+0xac/0x100 \t  invoke_syscall+0x6c/0x258 \t  el0_svc_common.constprop.0+0x160/0x22c \t  do_el0_svc+0x44/0x5c \t  el0_svc+0x48/0xb8 \t  el0t_64_sync_handler+0x13c/0x158 \t  el0t_64_sync+0x190/0x194 \t Code: f2fbffe1 a90157f4 12000802 aa0003f5 (38e16861) \t ---[ end trace 0000000000000000 ]--- \t Kernel panic - not syncing: Oops: Fatal exception","modified":"2026-09-15T09:02:58.408320685Z","published":"2024-10-21T12:15:05.653Z","upstream":["CVE-2024-47688"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-47688"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-47688.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-47688.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}