CVE-2024-39478

MEDIUM

Linux Kernel - Allocation of Resources Without Limits or Throttling in RSA Text Data Buffer

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in subsequent operations.

Scores

CVSS v3 5.5
EPSS 0.0018
EPSS Percentile 8.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (8)
linux/Kernel 6.5.0 - 6.9.5linux
Linux/Linux < 6.5
Linux/Linux 445a4aaf5842073e4130b1d6dbe3785284d9615f - 5944de192663f272033501dcd322b008fca72006
Linux/Linux 445a4aaf5842073e4130b1d6dbe3785284d9615f - d7f01649f4eaf1878472d3d3f480ae1e50d98f6c
Linux/Linux 6.10
Linux/Linux 6.5
Linux/Linux 6.9.5 - 6.9.*
linux/linux_kernel 6.9 - 6.9.5
Published Jul 05, 2024
Tracked Since Feb 18, 2026