cbcvebase.
CVE-2024-33619
published 2024-06-21

CVE-2024-33619: In the Linux kernel, the following vulnerability has been resolved: efi: libstub: only free priv.runtime_map when allocated priv.runtime_map is only allocated…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.4th percentile
In the Linux kernel, the following vulnerability has been resolved: efi: libstub: only free priv.runtime_map when allocated priv.runtime_map is only allocated when efi_novamap is not set. Otherwise, it is an uninitialized value. In the error path, it is freed unconditionally. Avoid passing an uninitialized value to free_pool. Free priv.runtime_map only when it was allocated. This bug was discovered and resolved using Coverity Static Analysis Security Testing (SAST) by Synopsys, Inc.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= f80d26043af91ceb5036c478101c015edb9e7630 < b8938d6f570f010a1dcdbfed3e5b5d3258c2a908b8938d6f570f010a1dcdbfed3e5b5d3258c2a908
linuxlinux>= f80d26043af91ceb5036c478101c015edb9e7630 < 9dce01f386c9ce6990c0a83fa14b1c95330b037e9dce01f386c9ce6990c0a83fa14b1c95330b037e
linuxlinux>= f80d26043af91ceb5036c478101c015edb9e7630 < 6ca67a5fe1c606d1fbe24c30a9fc0bdc43a185546ca67a5fe1c606d1fbe24c30a9fc0bdc43a18554
linuxlinux>= f80d26043af91ceb5036c478101c015edb9e7630 < 4b2543f7e1e6b91cfc8dd1696e3cdf01c3ac89744b2543f7e1e6b91cfc8dd1696e3cdf01c3ac8974
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.1 < 6.1.936.1.93
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.9.46.9.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.