CVE-2024-49853

HIGH

Linux Kernel 5.18-6.1.112, 6.2-6.6.53, 6.7-6.10.12, 6.11.0-6.11.1 - Use-After-Free in OPTEE SMC Transport

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix double free in OPTEE transport Channels can be shared between protocols, avoid freeing the same channel descriptors twice when unloading the stack.

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 12.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-415
Status published
Products (17)
linux/Kernel 5.18.0 - 6.1.113linux
linux/Kernel 6.11.0 - 6.11.2linux
linux/Kernel 6.2.0 - 6.6.54linux
linux/Kernel 6.7.0 - 6.10.13linux
Linux/Linux < 5.18
Linux/Linux 5.18
Linux/Linux 5f90f189a052f6fc46048f6ce29a37b709548b81 - 6699567b0bbb378600a4dc0a1f929439a4e84a2c
Linux/Linux 5f90f189a052f6fc46048f6ce29a37b709548b81 - aef6ae124bb3cc12e34430fed91fbb7efd7a444d
Linux/Linux 5f90f189a052f6fc46048f6ce29a37b709548b81 - d7f4fc2bc101e666da649605a9ece2bd42529c7a
Linux/Linux 5f90f189a052f6fc46048f6ce29a37b709548b81 - dc9543a4f2a5498a4a12d6d2427492a6f1a28056
... and 7 more
Published Oct 21, 2024
Tracked Since Feb 18, 2026