CVE-2024-27074Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
OSV7.0OSV6.5
EPSS
0.0%
top 99.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1
Latest updateNov 19

Description

In the Linux kernel, the following vulnerability has been resolved: media: go7007: fix a memleak in go7007_load_encoder In go7007_load_encoder, bounce(i.e. go->boot_fw), is allocated without a deallocation thereafter. After the following call chain: saa7134_go7007_init |-> go7007_boot_encoder |-> go7007_load_encoder |-> kfree(go) go is freed and thus bounce is leaked.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

NVDlinux/linux_kernel3.104.19.311+7
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-189.209+4
CVEListV5linux/linux95ef39403f890360a3e48fe550d8e8e5d088ad747f11dd3d165b178e738fe73dfeea513e383bedb5+9
debiandebian/linux< linux 6.1.85-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

29
OSV
linux-oracle vulnerabilities2025-11-19
OSV
linux-aws-fips vulnerabilities2025-09-24
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities2025-09-17
OSV
linux-fips, linux-azure-fips, linux-gcp-fips vulnerabilities2025-09-17
OSV
linux-aws vulnerabilities2025-09-02

📋Vendor Advisories

30
Ubuntu
Linux kernel (Oracle) vulnerabilities2025-11-19
Ubuntu
Linux kernel (AWS FIPS) vulnerabilities2025-09-24
Ubuntu
Linux kernel vulnerabilities2025-09-17
Ubuntu
Linux kernel (FIPS) vulnerabilities2025-09-17
Ubuntu
Linux kernel (AWS) vulnerabilities2025-09-02

💬Community

1
Bugzilla
CVE-2024-27074 kernel: media: go7007: fix a memleak in go7007_load_encoder2024-05-01