In the Linux kernel, the following vulnerability has been resolved:
HID: hyperv: streamline driver probe to avoid devres issues
It was found that unloading 'hid_hyperv' module results in a devres complaint:
... hvvmbus: unregistering driver hidhyperv ------------[ cut here ]------------ WARNING: CPU: 2 PID: 3983 at drivers/base/devres.c:691 devresreleasegroup+0x1f2/0x2c0 ... Call Trace: <TASK> ? devresreleasegroup+0x1f2/0x2c0 ? _warn+0xd1/0x1c0 ? devresreleasegroup+0x1f2/0x2c0 ? reportbug+0x32a/0x3c0 ? handlebug+0x53/0xa0 ? excinvalidop+0x18/0x50 ? asmexcinvalidop+0x1a/0x20 ? devresreleasegroup+0x1f2/0x2c0 ? devresreleasegroup+0x90/0x2c0 ? rcuiswatching+0x15/0xb0 ? _pfxdevresreleasegroup+0x10/0x10 hiddeviceremove+0xf5/0x220 devicereleasedriverinternal+0x371/0x540 ? klistput+0xf3/0x170 busremovedevice+0x1f1/0x3f0 devicedel+0x33f/0x8c0 ? _pfxdevicedel+0x10/0x10 ? cleanupsrcustruct+0x337/0x500 hiddestroydevice+0xc8/0x130 mousevscremove+0xd2/0x1d0 [hidhyperv] devicereleasedriverinternal+0x371/0x540 driverdetach+0xc5/0x180 busremovedriver+0x11e/0x2a0 ? _mutexunlockslowpath+0x160/0x5e0 vmbusdriverunregister+0x62/0x2b0 [hvvmbus] ...
And the issue seems to be that the corresponding devres group is not allocated. Normally, devresopengroup() is called from _hiddeviceprobe() but Hyper-V HID driver overrides 'hiddev->driver' with 'mousevschiddriver' stub and basically re-implements _hiddeviceprobe() by calling hidparse() and hidhwstart() but not devresopengroup(). hiddeviceprobe() does not call _hiddeviceprobe() for it. Later, when the driver is removed, hiddeviceremove() calls devresrelease_group() as it doesn't check whether hdev->driver was initially overridden or not.
The issue seems to be related to the commit 62c68e7cee33 ("HID: ensure timely release of driver-allocated resources") but the commit itself seems to be correct.
Fix the issue by dropping the 'hiddev->driver' override and using hidregisterdriver()/hidunregisterdriver() instead. Alternatively, it would have been possible to rely on the default handling but HIDCONNECTDEFAULT implies HIDCONNECT_HIDRAW and it doesn't seem to work for mousevsc as-is.
[
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66ef47faa90d838cda131fe1f7776456cc3b59f2",
"id": "CVE-2024-56545-0be47f5d",
"signature_version": "v1",
"target": {
"function": "mousevsc_exit",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "278897231181605708536005116327339422109",
"length": 65.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3d48d0fbaaa74a04fb9092780a3f83dc4f3f8160",
"id": "CVE-2024-56545-0f2c8668",
"signature_version": "v1",
"target": {
"function": "mousevsc_exit",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "278897231181605708536005116327339422109",
"length": 65.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b03e713a400aeb5f969bab4daf47a7402d0df814",
"id": "CVE-2024-56545-17d69e83",
"signature_version": "v1",
"target": {
"function": "mousevsc_init",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "37521187854733175943027921423233648065",
"length": 72.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@19a9457e5e210e408c1f8865b5d93c5a2c90409d",
"id": "CVE-2024-56545-36a85721",
"signature_version": "v1",
"target": {
"function": "mousevsc_exit",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "278897231181605708536005116327339422109",
"length": 65.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3d48d0fbaaa74a04fb9092780a3f83dc4f3f8160",
"id": "CVE-2024-56545-3734cf33",
"signature_version": "v1",
"target": {
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Line",
"digest": {
"line_hashes": [
"337698402015732059453099179966531320724",
"78243079814831939954367212083653170875",
"83275619297907887156278367124213645224",
"162622060822515373533959388634827079380",
"69653156737635184147615598500524927649",
"212547446259682766358468469099136986403",
"326018236899202436798517010556804570099",
"118167509534036778222759391771670277883",
"146816336437491253039870646186683497574",
"287198924827630246391856981700884160338",
"220462885818364460785674711221547329170",
"177420664339134866456695127597437285946",
"205422599124244525533792530970339868086",
"293038342815176472115755373601065944989",
"4028340793249728376969336710394838572",
"83988526246541230803710633600319844015",
"163025099874291511842777765652497117821",
"329186578747971824640615392612978039856",
"308241660293369874828165598994025134640",
"205557767932534046379046135998521038580",
"228100759069343147717075273269005796281",
"274213364194022882556699581125069862790",
"34819234490535006244672712163509297492",
"205319091243916774312921595379941356108",
"44564464142712595348384230645760320905",
"127353684169187487065489338994678872268",
"181723492262750881177657320177274358415",
"58926897547664751003255493057056903073",
"172537882574202974880898095926313198135",
"185042509510651305744563618152625387125",
"300295064163157455828041511869214961385",
"88258490998774901643016237870973352264"
],
"threshold": 0.9
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66ef47faa90d838cda131fe1f7776456cc3b59f2",
"id": "CVE-2024-56545-505ce7b1",
"signature_version": "v1",
"target": {
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Line",
"digest": {
"line_hashes": [
"337698402015732059453099179966531320724",
"78243079814831939954367212083653170875",
"83275619297907887156278367124213645224",
"162622060822515373533959388634827079380",
"69653156737635184147615598500524927649",
"212547446259682766358468469099136986403",
"326018236899202436798517010556804570099",
"118167509534036778222759391771670277883",
"146816336437491253039870646186683497574",
"287198924827630246391856981700884160338",
"220462885818364460785674711221547329170",
"177420664339134866456695127597437285946",
"205422599124244525533792530970339868086",
"293038342815176472115755373601065944989",
"4028340793249728376969336710394838572",
"83988526246541230803710633600319844015",
"163025099874291511842777765652497117821",
"329186578747971824640615392612978039856",
"308241660293369874828165598994025134640",
"205557767932534046379046135998521038580",
"228100759069343147717075273269005796281",
"274213364194022882556699581125069862790",
"34819234490535006244672712163509297492",
"205319091243916774312921595379941356108",
"44564464142712595348384230645760320905",
"127353684169187487065489338994678872268",
"181723492262750881177657320177274358415",
"58926897547664751003255493057056903073",
"172537882574202974880898095926313198135",
"185042509510651305744563618152625387125",
"300295064163157455828041511869214961385",
"88258490998774901643016237870973352264"
],
"threshold": 0.9
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66ef47faa90d838cda131fe1f7776456cc3b59f2",
"id": "CVE-2024-56545-6c0da071",
"signature_version": "v1",
"target": {
"function": "mousevsc_probe",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "11600433150067761162465174178820357096",
"length": 1474.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3d48d0fbaaa74a04fb9092780a3f83dc4f3f8160",
"id": "CVE-2024-56545-7155c792",
"signature_version": "v1",
"target": {
"function": "mousevsc_init",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "37521187854733175943027921423233648065",
"length": 72.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@19a9457e5e210e408c1f8865b5d93c5a2c90409d",
"id": "CVE-2024-56545-77d95907",
"signature_version": "v1",
"target": {
"function": "mousevsc_init",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "37521187854733175943027921423233648065",
"length": 72.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@66ef47faa90d838cda131fe1f7776456cc3b59f2",
"id": "CVE-2024-56545-7d745644",
"signature_version": "v1",
"target": {
"function": "mousevsc_init",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "37521187854733175943027921423233648065",
"length": 72.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b03e713a400aeb5f969bab4daf47a7402d0df814",
"id": "CVE-2024-56545-9d83ef40",
"signature_version": "v1",
"target": {
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Line",
"digest": {
"line_hashes": [
"337698402015732059453099179966531320724",
"78243079814831939954367212083653170875",
"83275619297907887156278367124213645224",
"162622060822515373533959388634827079380",
"69653156737635184147615598500524927649",
"212547446259682766358468469099136986403",
"326018236899202436798517010556804570099",
"118167509534036778222759391771670277883",
"146816336437491253039870646186683497574",
"287198924827630246391856981700884160338",
"220462885818364460785674711221547329170",
"177420664339134866456695127597437285946",
"205422599124244525533792530970339868086",
"293038342815176472115755373601065944989",
"4028340793249728376969336710394838572",
"83988526246541230803710633600319844015",
"163025099874291511842777765652497117821",
"329186578747971824640615392612978039856",
"308241660293369874828165598994025134640",
"205557767932534046379046135998521038580",
"228100759069343147717075273269005796281",
"274213364194022882556699581125069862790",
"34819234490535006244672712163509297492",
"205319091243916774312921595379941356108",
"44564464142712595348384230645760320905",
"127353684169187487065489338994678872268",
"181723492262750881177657320177274358415",
"58926897547664751003255493057056903073",
"172537882574202974880898095926313198135",
"185042509510651305744563618152625387125",
"300295064163157455828041511869214961385",
"88258490998774901643016237870973352264"
],
"threshold": 0.9
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@19a9457e5e210e408c1f8865b5d93c5a2c90409d",
"id": "CVE-2024-56545-aed38e7c",
"signature_version": "v1",
"target": {
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Line",
"digest": {
"line_hashes": [
"337698402015732059453099179966531320724",
"78243079814831939954367212083653170875",
"83275619297907887156278367124213645224",
"162622060822515373533959388634827079380",
"69653156737635184147615598500524927649",
"212547446259682766358468469099136986403",
"326018236899202436798517010556804570099",
"118167509534036778222759391771670277883",
"146816336437491253039870646186683497574",
"287198924827630246391856981700884160338",
"220462885818364460785674711221547329170",
"177420664339134866456695127597437285946",
"205422599124244525533792530970339868086",
"293038342815176472115755373601065944989",
"4028340793249728376969336710394838572",
"83988526246541230803710633600319844015",
"163025099874291511842777765652497117821",
"329186578747971824640615392612978039856",
"308241660293369874828165598994025134640",
"205557767932534046379046135998521038580",
"228100759069343147717075273269005796281",
"274213364194022882556699581125069862790",
"34819234490535006244672712163509297492",
"205319091243916774312921595379941356108",
"44564464142712595348384230645760320905",
"127353684169187487065489338994678872268",
"181723492262750881177657320177274358415",
"58926897547664751003255493057056903073",
"172537882574202974880898095926313198135",
"185042509510651305744563618152625387125",
"300295064163157455828041511869214961385",
"88258490998774901643016237870973352264"
],
"threshold": 0.9
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3d48d0fbaaa74a04fb9092780a3f83dc4f3f8160",
"id": "CVE-2024-56545-b44dd7d0",
"signature_version": "v1",
"target": {
"function": "mousevsc_probe",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "11600433150067761162465174178820357096",
"length": 1474.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b03e713a400aeb5f969bab4daf47a7402d0df814",
"id": "CVE-2024-56545-d39f3012",
"signature_version": "v1",
"target": {
"function": "mousevsc_exit",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "278897231181605708536005116327339422109",
"length": 65.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b03e713a400aeb5f969bab4daf47a7402d0df814",
"id": "CVE-2024-56545-dfec6193",
"signature_version": "v1",
"target": {
"function": "mousevsc_probe",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "11600433150067761162465174178820357096",
"length": 1474.0
}
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@19a9457e5e210e408c1f8865b5d93c5a2c90409d",
"id": "CVE-2024-56545-f7569467",
"signature_version": "v1",
"target": {
"function": "mousevsc_probe",
"file": "drivers/hid/hid-hyperv.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "11600433150067761162465174178820357096",
"length": 1474.0
}
}
]