CVE-2024-35792

HIGH

Linux Kernel 6.6-6.6.23, 6.7-6.7.11 - Use-After-Free in crypto rk3288 unprepare

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: rk3288 - Fix use after free in unprepare The unprepare call must be carried out before the finalize call as the latter can free the request.

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 12.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (12)
linux/Kernel 6.6.0 - 6.6.24linux
linux/Kernel 6.7.0 - 6.7.12linux
Linux/Linux < 6.6
Linux/Linux 6.6
Linux/Linux 6.6.24 - 6.6.*
Linux/Linux 6.7.12 - 6.7.*
Linux/Linux 6.8
Linux/Linux c66c17a0f69b0e017bbc01d999a28ed96ee84826 - 48dd260fdb728eda4a246f635d1325e82f0d3555
Linux/Linux c66c17a0f69b0e017bbc01d999a28ed96ee84826 - c0afb6b88fbbc177fa322a835f874be217bffe45
Linux/Linux c66c17a0f69b0e017bbc01d999a28ed96ee84826 - eb2a41a8ae8c8c4f68aef3bd94665c0cf23e04be
... and 2 more
Published May 17, 2024
Tracked Since Feb 18, 2026