cbcvebase.
CVE-2024-56538
published 2024-12-27

CVE-2024-56538: In the Linux kernel, the following vulnerability has been resolved: drm: zynqmp_kms: Unplug DRM device before removal Prevent userspace accesses to the DRM…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.1th percentile
In the Linux kernel, the following vulnerability has been resolved: drm: zynqmp_kms: Unplug DRM device before removal Prevent userspace accesses to the DRM device from causing use-after-frees by unplugging the device before we remove it. This causes any further userspace accesses to result in an error without further calls into this driver's internals.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.3-1 (forky)linux 6.12.3-1 (forky)
linuxlinux
linuxlinux>= d76271d22694e874ed70791702db9252ffe96a4c < a17b9afe58c474657449cf87e238b1788200576ba17b9afe58c474657449cf87e238b1788200576b
linuxlinux>= d76271d22694e874ed70791702db9252ffe96a4c < 4fb97432e28a7e136b2d76135d50e988ada8e1af4fb97432e28a7e136b2d76135d50e988ada8e1af
linuxlinux>= d76271d22694e874ed70791702db9252ffe96a4c < 692f52aedccbf79b212a1e14e3735192b4c24a7d692f52aedccbf79b212a1e14e3735192b4c24a7d
linuxlinux>= d76271d22694e874ed70791702db9252ffe96a4c < 2e07c88914fc5289c21820b1aa94f058feb381972e07c88914fc5289c21820b1aa94f058feb38197
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.9 < 6.6.646.6.64
linuxlinux_kernel>= 6.12 < 6.12.26.12.2
linuxlinux_kernel>= 6.7 < 6.11.116.11.11
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.64.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0
ubuntulinux-azure-5.15
ubuntulinux-intel-iotg-5.15
ubuntulinux-xilinx-zynqmp

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.