CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-50176: remoteproc: k3-r5: Fix error handling when power-up failed

5.5 CVSS

Description

In the Linux kernel, the following vulnerability has been resolved:

remoteproc: k3-r5: Fix error handling when power-up failed

By simply bailing out, the driver was violating its rule and internal
assumptions that either both or no rproc should be initialized. E.g.,
this could cause the first core to be available but not the second one,
leading to crashes on its shutdown later on while trying to dereference
that second instance.

Classification

CVE ID: CVE-2024-50176

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.5

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 5.11% (scored less or equal to compared to others)

EPSS Date: 2025-06-02 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-50176
https://git.kernel.org/stable/c/87ab3af7447791d0c619610fd560bd804549e187
https://git.kernel.org/stable/c/fc71c23958931713b5e76f317b76be37189f2516
https://git.kernel.org/stable/c/afd102bde99d90ef41e043c846ea34b04433eb7b
https://git.kernel.org/stable/c/7afb5e3aa989c479979faeb18768a67889a7a9c6
https://git.kernel.org/stable/c/9ab27eb5866ccbf57715cfdba4b03d57776092fb

Timeline