---
cve: "CVE-2024-44971"
severity: "LOW"
cvss: 3.1
epss: "0.2%"
vendor: "Linux"
kev: false
exploited: false
published: "2024-09-04 18:56:47"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T05:35:40+02:00"
---

# CVE-2024-44971

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register()

bcm_sf2_mdio_register() calls of_phy_find_device() and then
phy_device_remove() in a loop to remove existing PHY devices.
of_phy_find_device() eventually calls bus_find_device(), which calls
get_device() on the returned struct device * to increment the refcount.
The current implementation does not decrement the refcount, which causes
memory leak.

This commit adds the missing phy_device_free() call to decrement the
refcount via put_device() to balance the refcount.

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.224
- Kernel ≥ 5.15.165
- Kernel ≥ 6.1.105
- Kernel ≥ 6.6.46
- Kernel ≥ 6.10.5

## Referenzen

- <https://git.kernel.org/stable/c/b7b8d9f5e679af60c94251fd6728dde34be69a71>
- <https://git.kernel.org/stable/c/c05516c072903f6fb9134b8e7e1ad4bffcdc4819>
- <https://git.kernel.org/stable/c/7feef10768ea71d468d9bbc1e0d14c461876768c>
- <https://git.kernel.org/stable/c/a7d2808d67570e6acae45c2a96e0d59986888e4c>
- <https://git.kernel.org/stable/c/f3d5efe18a11f94150fee8b3fda9d62079af640a>
- <https://git.kernel.org/stable/c/e3862093ee93fcfbdadcb7957f5f8974fffa806a>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-44971) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
