CVE-2024-42263

MEDIUM

Linux Kernel 6.8-6.10.3 - Use-After-Free in DRM V3D Timestamp Extension

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix potential memory leak in the timestamp extension If fetching of userspace memory fails during the main loop, all drm sync objs looked up until that point will be leaked because of the missing drm_syncobj_put. Fix it by exporting and using a common cleanup helper. (cherry picked from commit 753ce4fea62182c77e1691ab4f9022008f25b62e)

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 9.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (9)
linux/Kernel 6.8.0 - 6.10.4linux
Linux/Linux < 6.8
Linux/Linux 6.10.4 - 6.10.*
Linux/Linux 6.11
Linux/Linux 6.8
Linux/Linux 9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f - 0e50fcc20bd87584840266e8004f9064a8985b4f
Linux/Linux 9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f - 9b5033ee2c5af6d1135a403df32d219ab57e55f9
linux/linux_kernel 6.11 rc1
linux/linux_kernel 6.8 - 6.10.4
Published Aug 17, 2024
Tracked Since Feb 18, 2026