In the Linux kernel, the following vulnerability has been resolved:leds: mlxreg: Use devm_mutex_init() for mutex initializationIn this driver LEDs are registered using devm_led_classdev_register()so they are automatically unregistered after module's remove() is done.led_classdev_unregister() calls module's led_set_brightness() to turn offthe LEDs and that callback uses mutex which was destroyed alreadyin module's remove() so use devm API instead.
No PoCs from references.
- https://github.com/w4zu/Debian_security