CVE-2024-57872

MEDIUM

Linux Kernel 3.10-6.12.4 - Use-After-Free in UFS Platform HBA Deallocation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: pltfrm: Dellocate HBA during ufshcd_pltfrm_remove() This will ensure that the scsi host is cleaned up properly using scsi_host_dev_release(). Otherwise, it may lead to memory leaks.

Scores

CVSS v3 5.5
EPSS 0.0018
EPSS Percentile 7.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (9)
linux/Kernel 3.10.0 - 6.12.5linux
Linux/Linux < 3.10
Linux/Linux 03b1781aa978aab345b5a85d8596f8615281ba89 - 897df60c16d54ad515a3d0887edab5c63da06d1f
Linux/Linux 03b1781aa978aab345b5a85d8596f8615281ba89 - cd188519d2467ab4c2141587b0551ba030abff0e
Linux/Linux 3.10
Linux/Linux 6.12.5 - 6.12.*
Linux/Linux 6.13
linux/linux_kernel 6.13 rc1
linux/linux_kernel 3.10 - 6.12.5
Published Jan 11, 2025
Tracked Since Feb 18, 2026