CVE-2024-49991

HIGH

Linux Kernel - Use-After-Free in amdkfd_free_gtt_mem

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer Pass pointer reference to amdgpu_bo_unref to clear the correct pointer, otherwise amdgpu_bo_unref clear the local variable, the original pointer not set to NULL, this could cause use-after-free bug.

Scores

CVSS v3 7.8
EPSS 0.0026
EPSS Percentile 16.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (18)
debian/debian_linux 11.0
linux/Kernel 4.3.0 - 6.1.118linux
linux/Kernel 6.11.0 - 6.11.3linux
linux/Kernel 6.2.0 - 6.6.55linux
linux/Kernel 6.7.0 - 6.10.14linux
Linux/Linux < 4.3
Linux/Linux 130e0371b7d454bb4a861253c822b9f911ad5d19 - 30ceb873cc2e97348d9da2265b2d1ddf07f682e1
Linux/Linux 130e0371b7d454bb4a861253c822b9f911ad5d19 - 6c9289806591807e4e3be9a23df8ee2069180055
Linux/Linux 130e0371b7d454bb4a861253c822b9f911ad5d19 - 71f3240f82987f0f070ea5bed559033de7d4c0e1
Linux/Linux 130e0371b7d454bb4a861253c822b9f911ad5d19 - c86ad39140bbcb9dc75a10046c2221f657e8083b
... and 8 more
Published Oct 21, 2024
Tracked Since Feb 18, 2026