Review reviewHigh

CVE-2024-58093

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstream function removal Before 456d8aa37d0f ("PCI/ASPM: Disable ASPM on MFD function removal to avoid use-after-free"), we would free the ASPM link only after the last function on the bus pertaining to the given link was removed. That was too late. If function 0 is removed before sibling function, link->downstream would point to free'd memory after. After above change, we freed the ASPM parent link state upon any function removal on the bus pertaining to a given link. That is to...

CVSS
7.8
EPSS
0.20%
10.2% percentile
CISA KEV
Not listed
Published
2025.04.17
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.20%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstream function removal Before 456d8aa37d0f ("PCI/ASPM: Disable ASPM on MFD function removal to avoid use-after-free"), we would free the ASPM link only after the last function on the bus pertaining to the given link was removed. That was too late. If function 0 is removed before sibling function, link->downstream would point to free'd memory after. After above change, we freed the ASPM parent link state upon any function removal on the bus pertaining to a given link. That is to...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 666e7f9d60cee23077ea3e6331f6f8a19f7ea03f < 0a0f9aecf66b98959aab7fb5764b4b3e522f4f5b, >= 7badf4d6f49a358a01ab072bbff88d3ee886c33b < 62db339ecc3d58d8fd83a9e4d80061cd943bb6e2, >= 9856c0de49052174ab474113f4ba40c02aaee086 < e5cd58f61e9d8024ee11bd78c12c8916891d4077, >= 7aecdd47910c51707696e8b0e045b9f88bd4230f < cd4b07507794f7ad1a74e12eca75121d98187e66, >= 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 < 8b930ddc2044e36866c41423e89889e0258695a3, >= 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 < f556b6ba0ac5f8353287ce6ed761228f0b4fafb7, >= 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 < ba4cdc14c0d4df00d3e99bff7fe545303db98183, >= 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 < 4d96930239981f312821a4065db8cc0f8240a173, >= 456d8aa37d0f56fc9e985e812496e861dcd6f2f2 < cbf937dcadfd571a434f8074d057b32cd14fbea5, >= d51d2eeae4ce54d542909c4d9d07bf371a78592c, >= 4203722d51afe3d239e03f15cc73efdf023a7103, >= 5.4.251 < 5.4.292, >= 5.10.188 < 5.10.236, >= 5.15.121 < 5.15.180, >= 6.1.39 < 6.1.134, >= 6.3.13 < 6.4, >= 6.4.4 < 6.5, >= 6.5, >= 5.4.251 < 5.5, >= 5.10.188 < 5.11
Fixed versions
5.5, 5.11, 5.16, 6.2, 6.4, 6.15

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2024-58093 — Linux Linux, linux kernel | SECUFOCUS NOW