cbcvebase.
CVE-2024-50071
published 2024-10-29

CVE-2024-50071: In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: fix a double free in ma35_pinctrl_dt_node_to_map_func() 'new_map' is…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
9.9th percentile
In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: fix a double free in ma35_pinctrl_dt_node_to_map_func() 'new_map' is allocated using devm_* which takes care of freeing the allocated data on device removal, call to .dt_free_map = pinconf_generic_dt_free_map double frees the map as pinconf_generic_dt_free_map() calls pinctrl_utils_free_map(). Fix this by using kcalloc() instead of auto-managed devm_kcalloc().

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.5-1 (forky)linux 6.11.5-1 (forky)
linuxlinux
linuxlinux>= f805e356313bbcafef48808c14eb9ce7f4ff2560 < 6441d9c3d71b59c8fd27d4e381c7471a32ac1a686441d9c3d71b59c8fd27d4e381c7471a32ac1a68
linuxlinux>= f805e356313bbcafef48808c14eb9ce7f4ff2560 < 3fd976afe9743110f20a23f93b7ff9693f2be4bf3fd976afe9743110f20a23f93b7ff9693f2be4bf
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.11 < 6.11.56.11.5

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.