CVE-2024-35792

HIGH

Linux Kernel < 6.6.24 - Use After Free

Title source: rule

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: rk3288 - Fix use after free in unprepare The unprepare call must be carried out before the finalize call as the latter can free the request.

Scores

CVSS v3 7.8
EPSS 0.0010
EPSS Percentile 27.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-416
Status published

Affected Products (9)

linux/linux_kernel < 6.6.24
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/Kernel < 6.6.24linux
linux/Kernel < 6.7.12linux

Timeline

Published May 17, 2024
Tracked Since Feb 18, 2026