cbcvebase.
CVE-2024-36940
published 2024-05-30

CVE-2024-36940: In the Linux kernel, the following vulnerability has been resolved: pinctrl: core: delete incorrect free in pinctrl_enable() The "pctldev" struct is allocated…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved: pinctrl: core: delete incorrect free in pinctrl_enable() The "pctldev" struct is allocated in devm_pinctrl_register_and_init(). It's a devm_ managed pointer that is freed by devm_pinctrl_dev_release(), so freeing it in pinctrl_enable() will lead to a double free. The devm_pinctrl_dev_release() function frees the pindescs and destroys the mutex as well.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 6118714275f0a313ecc296a87ed1af32d9691bed < 735f4c6b6771eafe336404c157ca683ad72a040d735f4c6b6771eafe336404c157ca683ad72a040d
linuxlinux>= 6118714275f0a313ecc296a87ed1af32d9691bed < cdaa171473d98962ae86f2a663d398fda2fbeefdcdaa171473d98962ae86f2a663d398fda2fbeefd
linuxlinux>= 6118714275f0a313ecc296a87ed1af32d9691bed < 288bc4aa75f150d6f1ee82dd43c6da1b438b6068288bc4aa75f150d6f1ee82dd43c6da1b438b6068
linuxlinux>= 6118714275f0a313ecc296a87ed1af32d9691bed < 41f88ef8ba387a12f4a2b8c400b6c9e8e54b2cca41f88ef8ba387a12f4a2b8c400b6c9e8e54b2cca
linuxlinux>= 6118714275f0a313ecc296a87ed1af32d9691bed < ac7d65795827dc0cf7662384ed27caf4066bd72eac7d65795827dc0cf7662384ed27caf4066bd72e
linuxlinux>= 6118714275f0a313ecc296a87ed1af32d9691bed < 558c8039fdf596a584a92c171cbf3298919c448c558c8039fdf596a584a92c171cbf3298919c448c
linuxlinux>= 6118714275f0a313ecc296a87ed1af32d9691bed < f9f1e321d53e4c5b666b66e5b43da29841fb55baf9f1e321d53e4c5b666b66e5b43da29841fb55ba
linuxlinux>= 6118714275f0a313ecc296a87ed1af32d9691bed < 5038a66dad0199de60e5671603ea6623eb9e5c795038a66dad0199de60e5671603ea6623eb9e5c79
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.15.0-228.2404.15.0-228.240
linuxlinux_kernel>= 4.11 < 4.19.3144.19.314
linuxlinux_kernel>= 4.20 < 5.4.2765.4.276
linuxlinux_kernel>= 5.11 < 5.15.1595.15.159
linuxlinux_kernel>= 5.16 < 6.1.916.1.91
linuxlinux_kernel>= 5.5 < 5.10.2175.10.217

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.