CVE-2024-50176

medium

Description

In the Linux kernel, the following vulnerability has been resolved: remoteproc: k3-r5: Fix error handling when power-up failed By simply bailing out, the driver was violating its rule and internal assumptions that either both or no rproc should be initialized. E.g., this could cause the first core to be available but not the second one, leading to crashes on its shutdown later on while trying to dereference that second instance.

References

https://git.kernel.org/stable/c/fc71c23958931713b5e76f317b76be37189f2516

https://git.kernel.org/stable/c/afd102bde99d90ef41e043c846ea34b04433eb7b

https://git.kernel.org/stable/c/9ab27eb5866ccbf57715cfdba4b03d57776092fb

https://git.kernel.org/stable/c/87ab3af7447791d0c619610fd560bd804549e187

https://git.kernel.org/stable/c/7afb5e3aa989c479979faeb18768a67889a7a9c6

Details

Source: Mitre, NVD

Published: 2024-11-08

Updated: 2025-10-01

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00029