CVE-2024-42263
MEDIUMLinux Kernel 6.8-6.10.3 - Use-After-Free in DRM V3D Timestamp Extension
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix potential memory leak in the timestamp extension If fetching of userspace memory fails during the main loop, all drm sync objs looked up until that point will be leaked because of the missing drm_syncobj_put. Fix it by exporting and using a common cleanup helper. (cherry picked from commit 753ce4fea62182c77e1691ab4f9022008f25b62e)
References (2)
Core 2
Scores
CVSS v3
5.5
EPSS
0.0020
EPSS Percentile
9.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (9)
linux/Kernel
6.8.0 - 6.10.4linux
Linux/Linux
< 6.8
Linux/Linux
6.10.4 - 6.10.*
Linux/Linux
6.11
Linux/Linux
6.8
Linux/Linux
9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f - 0e50fcc20bd87584840266e8004f9064a8985b4f
Linux/Linux
9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f - 9b5033ee2c5af6d1135a403df32d219ab57e55f9
linux/linux_kernel
6.11 rc1
linux/linux_kernel
6.8 - 6.10.4
Published
Aug 17, 2024
Tracked Since
Feb 18, 2026