cbcvebase.
CVE-2024-42313
published 2024-08-17

CVE-2024-42313: In the Linux kernel, the following vulnerability has been resolved: media: venus: fix use after free in vdec_close There appears to be a possible use after…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.7th percentile
In the Linux kernel, the following vulnerability has been resolved: media: venus: fix use after free in vdec_close There appears to be a possible use after free with vdec_close(). The firmware will add buffer release work to the work queue through HFI callbacks as a normal part of decoding. Randomly closing the decoder device from userspace during normal decoding can incur a read after free for inst. Fix it by cancelling the work in vdec_close.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= af2c3834c8ca7cc65d15592ac671933df8848115 < ad8cf035baf29467158e0550c7a42b7bb43d1db6ad8cf035baf29467158e0550c7a42b7bb43d1db6
linuxlinux>= af2c3834c8ca7cc65d15592ac671933df8848115 < 72aff311194c8ceda934f24fd6f250b8827d756772aff311194c8ceda934f24fd6f250b8827d7567
linuxlinux>= af2c3834c8ca7cc65d15592ac671933df8848115 < 4c9d235630d35db762b85a4149bbb0be9d504c364c9d235630d35db762b85a4149bbb0be9d504c36
linuxlinux>= af2c3834c8ca7cc65d15592ac671933df8848115 < f8e9a63b982a8345470c225679af4ba86e4a7282f8e9a63b982a8345470c225679af4ba86e4a7282
linuxlinux>= af2c3834c8ca7cc65d15592ac671933df8848115 < da55685247f409bf7f976cc66ba2104df75d8dadda55685247f409bf7f976cc66ba2104df75d8dad
linuxlinux>= af2c3834c8ca7cc65d15592ac671933df8848115 < 66fa52edd32cdbb675f0803b3c4da10ea19b663566fa52edd32cdbb675f0803b3c4da10ea19b6635
linuxlinux>= af2c3834c8ca7cc65d15592ac671933df8848115 < 6a96041659e834dc0b172dda4b2df512d63920c26a96041659e834dc0b172dda4b2df512d63920c2
linuxlinux>= af2c3834c8ca7cc65d15592ac671933df8848115 < a0157b5aa34eb43ec4c5510f9c260bbb03be937ea0157b5aa34eb43ec4c5510f9c260bbb03be937e
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.13 < 4.19.3204.19.320
linuxlinux_kernel>= 4.20 < 5.4.2825.4.282
linuxlinux_kernel>= 5.11 < 5.15.1655.15.165
linuxlinux_kernel>= 5.16 < 6.1.1036.1.103
linuxlinux_kernel>= 5.5 < 5.10.2245.10.224
linuxlinux_kernel>= 6.2 < 6.6.446.6.44
linuxlinux_kernel>= 6.7 < 6.10.36.10.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.