CVE-2024-56754
In the Linux kernel, the following vulnerability has been resolved: crypto: caam - Fix the pointer passed to caam_qi_shutdown() The type of the last parameter given to devm_add_action_or_reset() is "struct caam_drv_private *", but in caam_qi_shutdown(),…
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: caam - Fix the pointer passed to caam_qi_shutdown() The type of the last parameter given to devm_add_action_or_reset() is "struct caam_drv_private *", but in caam_qi_shutdown(), it is casted to "struct device *". Pass the correct parameter to devm_add_action_or_reset() so that the resources are released as expected.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.21% probability · 12th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/1f8e2f597b918ca5827a5c6d00b819d064264d1cPatch
- https://git.kernel.org/stable/c/6187727e57aec122c8a99c464c74578c810cbe40Patch
- https://git.kernel.org/stable/c/66eddb8dcb61065c53098510165f14b54232bcc2Patch
- https://git.kernel.org/stable/c/84a185aea7b83f620699de0ea36907d588d89cf6Patch
- https://git.kernel.org/stable/c/ad39df0898d3f469776c19d99229be055cc2dceaPatch
- https://git.kernel.org/stable/c/ad980b04f51f7fb503530bd1cb328ba5e75a250ePatch
- https://git.kernel.org/stable/c/cc386170b3312fd7b5bc4a69a9f52d7f50814526Patch
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.