cbcvebase.
CVE-2024-36890
published 2024-05-30

CVE-2024-36890: In the Linux kernel, the following vulnerability has been resolved: mm/slab: make __free(kfree) accept error pointers Currently, if an automatically freed…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved: mm/slab: make __free(kfree) accept error pointers Currently, if an automatically freed allocation is an error pointer that will lead to a crash. An example of this is in wm831x_gpio_dbg_show(). 171 char *label __free(kfree) = gpiochip_dup_line_label(chip, i); 172 if (IS_ERR(label)) { 173 dev_err(wm831x->dev, "Failed to duplicate label\n"); 174 continue; 175 } The auto clean up function should check for error pointers as well, otherwise we're going to keep hitting issues like this.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 3c6cc62ce1265aa5623e2e1b29c0fe258bf6e232 < 9f6eb0ab4f95240589ee85fd9886a944cd3645b29f6eb0ab4f95240589ee85fd9886a944cd3645b2
linuxlinux>= 54da6a0924311c7cf5015533991e44fb8eb12773 < ac6cf3ce9b7d12acb7b528248df5f87caa25fcdcac6cf3ce9b7d12acb7b528248df5f87caa25fcdc
linuxlinux>= 54da6a0924311c7cf5015533991e44fb8eb12773 < 79cbe0be6c0317b215ddd8bd3e32f0afdac4854379cbe0be6c0317b215ddd8bd3e32f0afdac48543
linuxlinux>= 54da6a0924311c7cf5015533991e44fb8eb12773 < cd7eb8f83fcf258f71e293f7fc52a70be8ed0128cd7eb8f83fcf258f71e293f7fc52a70be8ed0128
linuxlinux>= 6.1.79 < 6.1.916.1.91
linuxlinux>= af53aaf20722d745a69a051114a1ae237f5b922e < edca32f87329d6e341d2143a3b58ec254e8f6b88edca32f87329d6e341d2143a3b58ec254e8f6b88
linuxlinux>= f550466949e822afcd0b546a4fc35795930660bc < 946771c2a2b1150f9b7286feadc3aa1e15a1eb16946771c2a2b1150f9b7286feadc3aa1e15a1eb16
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 6.1.79 < 6.1.916.1.91
linuxlinux_kernel>= 6.5 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.