cbcvebase.
CVE-2024-57887
published 2025-01-15

CVE-2024-57887: In the Linux kernel, the following vulnerability has been resolved: drm: adv7511: Fix use-after-free in adv7533_attach_dsi() The host_node pointer was assigned…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm: adv7511: Fix use-after-free in adv7533_attach_dsi() The host_node pointer was assigned and freed in adv7533_parse_dt(), and later, adv7533_attach_dsi() uses the same. Fix this use-after-free issue by dropping of_node_put() in adv7533_parse_dt() and calling of_node_put() in error path of probe() and also in the remove().

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= 1e4d58cd7f888522d16f221d628356befbb08468 < acec80d9f126cd3fa764bbe3d96bc0cb5cd2b087acec80d9f126cd3fa764bbe3d96bc0cb5cd2b087
linuxlinux>= 1e4d58cd7f888522d16f221d628356befbb08468 < d208571943ffddc438a7ce533d5d0b9219806242d208571943ffddc438a7ce533d5d0b9219806242
linuxlinux>= 1e4d58cd7f888522d16f221d628356befbb08468 < 1f49aaf55652580ae63ab83d67211fe6a55d83dc1f49aaf55652580ae63ab83d67211fe6a55d83dc
linuxlinux>= 1e4d58cd7f888522d16f221d628356befbb08468 < ca9d077350fa21897de8bf64cba23b198740aab5ca9d077350fa21897de8bf64cba23b198740aab5
linuxlinux>= 1e4d58cd7f888522d16f221d628356befbb08468 < 81adbd3ff21c1182e06aa02c6be0bfd9ea02d8e881adbd3ff21c1182e06aa02c6be0bfd9ea02d8e8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.9-16.12.9-1
linuxlinux_kernel>= 0 < 6.12.9-16.12.9-1
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 4.8 < 6.1.1256.1.125
linuxlinux_kernel>= 6.2 < 6.6.706.6.70
linuxlinux_kernel>= 6.7 < 6.12.96.12.9

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.