cbcvebase.
CVE-2024-50173
published 2024-11-08

CVE-2024-50173: In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix access to uninitialized variable in tick_ctx_cleanup() The group variable…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.6th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix access to uninitialized variable in tick_ctx_cleanup() The group variable can't be used to retrieve ptdev in our second loop, because it points to the previously iterated list_head, not a valid group. Get the ptdev object from the scheduler instead.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.4-1 (forky)linux 6.11.4-1 (forky)
linuxlinux
linuxlinux>= d72f049087d4f973f6332b599c92177e718107de < ac2ca5e5148a0d4d78ac01c2d8348d0757c7367fac2ca5e5148a0d4d78ac01c2d8348d0757c7367f
linuxlinux>= d72f049087d4f973f6332b599c92177e718107de < 3bde05794497d5f426d4ea2ecb9868bf7721fb243bde05794497d5f426d4ea2ecb9868bf7721fb24
linuxlinux>= d72f049087d4f973f6332b599c92177e718107de < 282864cc5d3f144af0cdea1868ee2dc2c5110f0d282864cc5d3f144af0cdea1868ee2dc2c5110f0d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.10 < 6.10.146.10.14
linuxlinux_kernel>= 6.11 < 6.11.36.11.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.