cbcvebase.
CVE-2024-27078
published 2024-05-01

CVE-2024-27078: In the Linux kernel, the following vulnerability has been resolved: media: v4l2-tpg: fix some memleaks in tpg_alloc In tpg_alloc, resources should be…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.1th percentile
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-tpg: fix some memleaks in tpg_alloc In tpg_alloc, resources should be deallocated in each and every error-handling paths, since they are allocated in for statements. Otherwise there would be memleaks because tpg_free is called only when tpg_alloc return 0.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 63881df94d3ecbb0deafa0b77da62ff2f32961c4 < 0de691ff547d86dd54c24b40a81f9c925df8dd770de691ff547d86dd54c24b40a81f9c925df8dd77
linuxlinux>= 63881df94d3ecbb0deafa0b77da62ff2f32961c4 < 8269ab16415f2065cd792c49b0475543936cbd798269ab16415f2065cd792c49b0475543936cbd79
linuxlinux>= 63881df94d3ecbb0deafa0b77da62ff2f32961c4 < 94303a06e1852a366e9671fff46d19459f88cb2894303a06e1852a366e9671fff46d19459f88cb28
linuxlinux>= 63881df94d3ecbb0deafa0b77da62ff2f32961c4 < 770a57922ce36a8476c43f7400b6501c554ea511770a57922ce36a8476c43f7400b6501c554ea511
linuxlinux>= 63881df94d3ecbb0deafa0b77da62ff2f32961c4 < 6bf5c2fade8ed53b2d26fa9875e5b04f36c7145d6bf5c2fade8ed53b2d26fa9875e5b04f36c7145d
linuxlinux>= 63881df94d3ecbb0deafa0b77da62ff2f32961c4 < 4c86c772fef06f5d7a66151bac42366825db09414c86c772fef06f5d7a66151bac42366825db0941
linuxlinux>= 63881df94d3ecbb0deafa0b77da62ff2f32961c4 < 31096da07933598da8522c54bd007376fb152a0931096da07933598da8522c54bd007376fb152a09
linuxlinux>= 63881df94d3ecbb0deafa0b77da62ff2f32961c4 < 622b1cf38521569869c8f7b9fbe9e4f1a289add7622b1cf38521569869c8f7b9fbe9e4f1a289add7
linuxlinux>= 63881df94d3ecbb0deafa0b77da62ff2f32961c4 < 8cf9c5051076e0eb958f4361d50d8b0c3ee6691c8cf9c5051076e0eb958f4361d50d8b0c3ee6691c
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 0 < 4.4.0-273.3074.4.0-273.307
linuxlinux_kernel>= 0 < 4.15.0-246.2584.15.0-246.258
linuxlinux_kernel>= 3.18 < 4.19.3114.19.311
linuxlinux_kernel>= 4.20 < 5.4.2735.4.273
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.5 < 5.10.2145.10.214

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.