CVE-2024-36959

MEDIUM

Linux Kernel 4.9.334-4.10 - Use-After-Free in pinctrl_dt_to_map()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() If we fail to allocate propname buffer, we need to drop the reference count we just took. Because the pinctrl_dt_free_maps() includes the droping operation, here we call it directly.

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 16.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (37)
linux/Kernel < 4.19.314linux
linux/Kernel 4.20.0 - 5.4.276linux
linux/Kernel 5.11.0 - 5.15.159linux
linux/Kernel 5.16.0 - 6.1.91linux
linux/Kernel 5.5.0 - 5.10.217linux
linux/Kernel 6.1.0 - 6.6.31linux
linux/Kernel 6.2.0 - 6.8.10linux
Linux/Linux < 6.1
Linux/Linux 040f726fecd88121f3b95e70369785ad452dddf9 - 47d253c485491caaf70d8cd8c0248ae26e42581f
Linux/Linux 4.14.300 - 4.15
... and 27 more
Published May 30, 2024
Tracked Since Feb 18, 2026