cbcvebase.
CVE-2024-27077
published 2024-05-01

CVE-2024-27077: In the Linux kernel, the following vulnerability has been resolved: media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity The entity->name (i.e. name)…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.1th percentile
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity The entity->name (i.e. name) is allocated in v4l2_m2m_register_entity but isn't freed in its following error-handling paths. This patch adds such deallocation to prevent memleak of entity->name.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= be2fff656322e82f215730839063c2c2ca73d14b < 3dd8abb0ed0e0a7c66d6d677c86ccb188cc393333dd8abb0ed0e0a7c66d6d677c86ccb188cc39333
linuxlinux>= be2fff656322e82f215730839063c2c2ca73d14b < 0175f2d34c85744f9ad6554f696cf0afb5bd04e40175f2d34c85744f9ad6554f696cf0afb5bd04e4
linuxlinux>= be2fff656322e82f215730839063c2c2ca73d14b < afd2a82fe300032f63f8be5d6cd6981e75f8bbf2afd2a82fe300032f63f8be5d6cd6981e75f8bbf2
linuxlinux>= be2fff656322e82f215730839063c2c2ca73d14b < dc866b69cc51af9b8509b4731b8ce2a4950cd0efdc866b69cc51af9b8509b4731b8ce2a4950cd0ef
linuxlinux>= be2fff656322e82f215730839063c2c2ca73d14b < 0c9550b032de48d6a7fa6a4ddc09699d64d9300d0c9550b032de48d6a7fa6a4ddc09699d64d9300d
linuxlinux>= be2fff656322e82f215730839063c2c2ca73d14b < 90029b9c979b60de5cb2b70ade4bbf61d561bc5d90029b9c979b60de5cb2b70ade4bbf61d561bc5d
linuxlinux>= be2fff656322e82f215730839063c2c2ca73d14b < 5dc319cc3c4f7b74f7dfba349aa26f87efb524585dc319cc3c4f7b74f7dfba349aa26f87efb52458
linuxlinux>= be2fff656322e82f215730839063c2c2ca73d14b < 9c23ef30e840fedc66948299509f6c2777c9cf4f9c23ef30e840fedc66948299509f6c2777c9cf4f
linuxlinux>= be2fff656322e82f215730839063c2c2ca73d14b < 8f94b49a5b5d386c038e355bef6347298aabd2118f94b49a5b5d386c038e355bef6347298aabd211
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 4.19 < 4.19.3114.19.311
linuxlinux_kernel>= 4.20 < 5.4.2735.4.273
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.5 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.