In the Linux kernel, the following vulnerability has been resolved:
net: dsa: bcmsf2: Fix a possible memory leak in bcmsf2mdioregister()
bcmsf2mdioregister() calls ofphyfinddevice() and then phydeviceremove() in a loop to remove existing PHY devices. ofphyfinddevice() eventually calls busfinddevice(), which calls getdevice() on the returned struct device * to increment the refcount. The current implementation does not decrement the refcount, which causes memory leak.
This commit adds the missing phydevicefree() call to decrement the refcount via put_device() to balance the refcount.
[
{
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "drivers/net/dsa/bcm_sf2.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a7d2808d67570e6acae45c2a96e0d59986888e4c",
"digest": {
"line_hashes": [
"108950212891044723662141741321685994810",
"175416394775944629677420929807391057928",
"7156412285302803394913184726544328789",
"55475542347365615045320054787552151302",
"39699854483916782893076197914329303631"
],
"threshold": 0.9
},
"id": "CVE-2024-44971-1387f7c5"
},
{
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "drivers/net/dsa/bcm_sf2.c",
"function": "bcm_sf2_mdio_register"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c05516c072903f6fb9134b8e7e1ad4bffcdc4819",
"digest": {
"length": 1870.0,
"function_hash": "5320276795186800414943563453098656651"
},
"id": "CVE-2024-44971-4b98b2f3"
},
{
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "drivers/net/dsa/bcm_sf2.c",
"function": "bcm_sf2_mdio_register"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7b8d9f5e679af60c94251fd6728dde34be69a71",
"digest": {
"length": 1870.0,
"function_hash": "5320276795186800414943563453098656651"
},
"id": "CVE-2024-44971-59a8f56e"
},
{
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "drivers/net/dsa/bcm_sf2.c",
"function": "bcm_sf2_mdio_register"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7feef10768ea71d468d9bbc1e0d14c461876768c",
"digest": {
"length": 1870.0,
"function_hash": "5320276795186800414943563453098656651"
},
"id": "CVE-2024-44971-7370198d"
},
{
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "drivers/net/dsa/bcm_sf2.c",
"function": "bcm_sf2_mdio_register"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f3d5efe18a11f94150fee8b3fda9d62079af640a",
"digest": {
"length": 1791.0,
"function_hash": "203291226151425263690876793859618458933"
},
"id": "CVE-2024-44971-a58c3eea"
},
{
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "drivers/net/dsa/bcm_sf2.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7feef10768ea71d468d9bbc1e0d14c461876768c",
"digest": {
"line_hashes": [
"108950212891044723662141741321685994810",
"175416394775944629677420929807391057928",
"7156412285302803394913184726544328789",
"55475542347365615045320054787552151302",
"39699854483916782893076197914329303631"
],
"threshold": 0.9
},
"id": "CVE-2024-44971-cf2b8dff"
},
{
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "drivers/net/dsa/bcm_sf2.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7b8d9f5e679af60c94251fd6728dde34be69a71",
"digest": {
"line_hashes": [
"108950212891044723662141741321685994810",
"175416394775944629677420929807391057928",
"7156412285302803394913184726544328789",
"55475542347365615045320054787552151302",
"39699854483916782893076197914329303631"
],
"threshold": 0.9
},
"id": "CVE-2024-44971-cf9b9084"
},
{
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "drivers/net/dsa/bcm_sf2.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c05516c072903f6fb9134b8e7e1ad4bffcdc4819",
"digest": {
"line_hashes": [
"108950212891044723662141741321685994810",
"175416394775944629677420929807391057928",
"7156412285302803394913184726544328789",
"55475542347365615045320054787552151302",
"39699854483916782893076197914329303631"
],
"threshold": 0.9
},
"id": "CVE-2024-44971-d1cbf835"
},
{
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "drivers/net/dsa/bcm_sf2.c",
"function": "bcm_sf2_mdio_register"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a7d2808d67570e6acae45c2a96e0d59986888e4c",
"digest": {
"length": 1870.0,
"function_hash": "5320276795186800414943563453098656651"
},
"id": "CVE-2024-44971-d2e7a752"
},
{
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "drivers/net/dsa/bcm_sf2.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f3d5efe18a11f94150fee8b3fda9d62079af640a",
"digest": {
"line_hashes": [
"108950212891044723662141741321685994810",
"175416394775944629677420929807391057928",
"7156412285302803394913184726544328789",
"315004362144999975881048438216070165261",
"219388407391737099196062413504867126365"
],
"threshold": 0.9
},
"id": "CVE-2024-44971-ef562f76"
}
]