cbcvebase.
CVE-2024-57904
published 2025-01-19

CVE-2024-57904: In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91: call input_free_device() on allocated iio_dev Current implementation of…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.0th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91: call input_free_device() on allocated iio_dev Current implementation of at91_ts_register() calls input_free_deivce() on st->ts_input, however, the err label can be reached before the allocated iio_dev is stored to st->ts_input. Thus call input_free_device() on input instead of st->ts_input.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= 84882b060301c35ab7e2c1ef355b0bd06b764195 < b549c90bfe66f704878aa1e57b30ba15dab71935b549c90bfe66f704878aa1e57b30ba15dab71935
linuxlinux>= 84882b060301c35ab7e2c1ef355b0bd06b764195 < ac8d932e3214c10ec641ad45a253929a596ead62ac8d932e3214c10ec641ad45a253929a596ead62
linuxlinux>= 84882b060301c35ab7e2c1ef355b0bd06b764195 < 028a1ba8e3bae593d701aee4f690ce7c195b67d6028a1ba8e3bae593d701aee4f690ce7c195b67d6
linuxlinux>= 84882b060301c35ab7e2c1ef355b0bd06b764195 < 25ef52f1c15db67d890b80203a911b9a57b0bf7125ef52f1c15db67d890b80203a911b9a57b0bf71
linuxlinux>= 84882b060301c35ab7e2c1ef355b0bd06b764195 < 09e067e3c83e0695d338e8a26916e3c2bc44be0209e067e3c83e0695d338e8a26916e3c2bc44be02
linuxlinux>= 84882b060301c35ab7e2c1ef355b0bd06b764195 < d115b7f3ddc03b38bb7e8754601556fe9b4fc034d115b7f3ddc03b38bb7e8754601556fe9b4fc034
linuxlinux>= 84882b060301c35ab7e2c1ef355b0bd06b764195 < de6a73bad1743e9e81ea5a24c178c67429ff510bde6a73bad1743e9e81ea5a24c178c67429ff510b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 3.16 < 5.4.2905.4.290
linuxlinux_kernel>= 5.11 < 5.15.1775.15.177
linuxlinux_kernel>= 5.16 < 6.1.1256.1.125
linuxlinux_kernel>= 5.5 < 5.10.2345.10.234
linuxlinux_kernel>= 6.2 < 6.6.726.6.72
linuxlinux_kernel>= 6.7 < 6.12.106.12.10

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.