cbcvebase.
CVE-2024-27039
published 2024-05-01

CVE-2024-27039: In the Linux kernel, the following vulnerability has been resolved: clk: hisilicon: hi3559a: Fix an erroneous devm_kfree() 'p_clk' is an array allocated just…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.2th percentile
In the Linux kernel, the following vulnerability has been resolved: clk: hisilicon: hi3559a: Fix an erroneous devm_kfree() 'p_clk' is an array allocated just before the for loop for all clk that need to be registered. It is incremented at each loop iteration. If a clk_register() call fails, 'p_clk' may point to something different from what should be freed. The best we can do, is to avoid this wrong release of memory.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 6c81966107dc0caa5d2ebedbcebb5f10d865064d < 3f8445f1c746fda180a7f75372ed06b24e9cefe23f8445f1c746fda180a7f75372ed06b24e9cefe2
linuxlinux>= 6c81966107dc0caa5d2ebedbcebb5f10d865064d < e0b0d1c46a2ce1e46b79d004a7270fdef872e097e0b0d1c46a2ce1e46b79d004a7270fdef872e097
linuxlinux>= 6c81966107dc0caa5d2ebedbcebb5f10d865064d < 95d1f1228c1bb54803ae57525b76db60e99b37e495d1f1228c1bb54803ae57525b76db60e99b37e4
linuxlinux>= 6c81966107dc0caa5d2ebedbcebb5f10d865064d < 2cc572e0085ebd4b662b74a0f43222bc00df9a002cc572e0085ebd4b662b74a0f43222bc00df9a00
linuxlinux>= 6c81966107dc0caa5d2ebedbcebb5f10d865064d < d575765b1b62e8bdb00af11caa1aabeb01763d9fd575765b1b62e8bdb00af11caa1aabeb01763d9f
linuxlinux>= 6c81966107dc0caa5d2ebedbcebb5f10d865064d < 64c6a38136b74a2f18c42199830975edd9fbc37964c6a38136b74a2f18c42199830975edd9fbc379
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.14 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.