cbcvebase.
CVE-2024-43900
published 2024-08-26

CVE-2024-43900: In the Linux kernel, the following vulnerability has been resolved: media: xc2028: avoid use-after-free in load_firmware_cb() syzkaller reported use-after-free…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.9th percentile
In the Linux kernel, the following vulnerability has been resolved: media: xc2028: avoid use-after-free in load_firmware_cb() syzkaller reported use-after-free in load_firmware_cb() [1]. The reason is because the module allocated a struct tuner in tuner_probe(), and then the module initialization failed, the struct tuner was released. A worker which created during module initialization accesses this struct tuner later, it caused use-after-free. The process is as follows: task-6504 worker_thread tuner_probe ffff8000d7ca2300: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ ffff8000d7ca2380: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ffff8000d7ca2400: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb [2] Actually, it is allocated for struct tuner, and dvb_frontend is inside.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 61a96113de51e1f8f43ac98cbeadb54e60045905 < ef517bdfc01818419f7bd426969a0c86b14f3e0eef517bdfc01818419f7bd426969a0c86b14f3e0e
linuxlinux>= 61a96113de51e1f8f43ac98cbeadb54e60045905 < 850304152d367f104d21c77cfbcc05806504218b850304152d367f104d21c77cfbcc05806504218b
linuxlinux>= 61a96113de51e1f8f43ac98cbeadb54e60045905 < 208deb6d8c3cb8c3acb1f41eb31cf68ea08726d5208deb6d8c3cb8c3acb1f41eb31cf68ea08726d5
linuxlinux>= 61a96113de51e1f8f43ac98cbeadb54e60045905 < 68594cec291ff9523b9feb3f43fd853dcddd1f6068594cec291ff9523b9feb3f43fd853dcddd1f60
linuxlinux_kernel< 6.1.1056.1.105
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 0 < 3.13.0-204.2553.13.0-204.255
linuxlinux_kernel>= 0 < 4.4.0-266.3004.4.0-266.300
linuxlinux_kernel>= 0 < 4.15.0-235.2474.15.0-235.247
linuxlinux_kernel>= 6.2 < 6.6.466.6.46
linuxlinux_kernel>= 6.7 < 6.10.56.10.5
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.