CVE-2024-27078Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
OSV7.0OSV6.5
EPSS
0.0%
top 99.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1
Latest updateFeb 12

Description

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-tpg: fix some memleaks in tpg_alloc In tpg_alloc, resources should be deallocated in each and every error-handling paths, since they are allocated in for statements. Otherwise there would be memleaks because tpg_free is called only when tpg_alloc return 0.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

NVDlinux/linux_kernel3.184.19.311+7
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-189.209+4
CVEListV5linux/linux63881df94d3ecbb0deafa0b77da62ff2f32961c40de691ff547d86dd54c24b40a81f9c925df8dd77+9
debiandebian/linux< linux 6.1.85-1 (bookworm)

Patches

🔴Vulnerability Details

31
OSV
linux-azure, linux-azure-fips vulnerabilities2026-02-12
OSV
linux-gcp-fips vulnerabilities2026-02-11
OSV
linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15 vulnerabilities2026-02-05
OSV
linux-aws-fips, linux-fips vulnerabilities2026-01-29
OSV
linux, linux-aws, linux-aws-hwe, linux-hwe, linux-kvm, linux-oracle vulnerabilities2026-01-29

📋Vendor Advisories

32
Ubuntu
Linux kernel (Azure) vulnerabilities2026-02-12
Ubuntu
Linux kernel (GCP FIPS) vulnerabilities2026-02-11
Ubuntu
Linux kernel vulnerabilities2026-02-05
Ubuntu
Linux kernel (FIPS) vulnerabilities2026-01-29
Ubuntu
Linux kernel vulnerabilities2026-01-29

💬Community

1
Bugzilla
CVE-2024-27078 kernel: media: v4l2-tpg: fix some memleaks in tpg_alloc2024-05-01
CVE-2024-27078 — Linux vulnerability | cvebase