cbcvebase.
CVE-2024-36959
published 2024-05-30

CVE-2024-36959: In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() If we fail to allocate…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.4th percentile
In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() If we fail to allocate propname buffer, we need to drop the reference count we just took. Because the pinctrl_dt_free_maps() includes the droping operation, here we call it directly.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 040f726fecd88121f3b95e70369785ad452dddf9 < 47d253c485491caaf70d8cd8c0248ae26e42581f47d253c485491caaf70d8cd8c0248ae26e42581f
linuxlinux>= 4.14.300 < 4.154.15
linuxlinux>= 4.19.267 < 4.19.3144.19.314
linuxlinux>= 4.9.334 < 4.104.10
linuxlinux>= 5.10.156 < 5.10.2175.10.217
linuxlinux>= 5.15.80 < 5.15.1595.15.159
linuxlinux>= 5.4.225 < 5.4.2765.4.276
linuxlinux>= 6.0.10 < 6.16.1
linuxlinux>= 777430aa4ddccaa5accec6db90ffc1d47f00d471 < 35ab679e8bb5a81a4f922d3efbd43e32bce6927435ab679e8bb5a81a4f922d3efbd43e32bce69274
linuxlinux>= 91d5c5060ee24fe8da88cd585bb43b843d2f0dce < 518d5ddafeb084d6d9b1773ed85164300037d0e6518d5ddafeb084d6d9b1773ed85164300037d0e6
linuxlinux>= 91d5c5060ee24fe8da88cd585bb43b843d2f0dce < 026e24cf31733dbd97f41cc9bc5273ace428eeec026e24cf31733dbd97f41cc9bc5273ace428eeec
linuxlinux>= 91d5c5060ee24fe8da88cd585bb43b843d2f0dce < c7e02ccc9fdc496fe51e440e3e66ac36509ca049c7e02ccc9fdc496fe51e440e3e66ac36509ca049
linuxlinux>= 91d5c5060ee24fe8da88cd585bb43b843d2f0dce < a0cedbcc8852d6c77b00634b81e41f17f29d9404a0cedbcc8852d6c77b00634b81e41f17f29d9404
linuxlinux>= 97e5b508e96176f1a73888ed89df396d7041bfcb < 76aa2440deb9a35507590f2c981a69a57ecd305d76aa2440deb9a35507590f2c981a69a57ecd305d
linuxlinux>= a988dcd3dd9e691c5ccc3324b209688f3b5453e9 < 06780473cb8a858d1d6cab2673e021b072a852d106780473cb8a858d1d6cab2673e021b072a852d1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.