cbcvebase.
CVE-2024-58055
published 2025-03-06

CVE-2024-58055: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: Don't free command immediately Don't prematurely free the command. Wait…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
13.1th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: Don't free command immediately Don't prematurely free the command. Wait for the status completion of the sense status. It can be freed then. Otherwise we will double-free the command.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= cff834c16d23d614388aab1b86d19eb67b3f80c4 < 7cb72dc08ed8da60fd6d1f6adf13bf0e6ee0f6947cb72dc08ed8da60fd6d1f6adf13bf0e6ee0f694
linuxlinux>= cff834c16d23d614388aab1b86d19eb67b3f80c4 < 38229c35a6d7875697dfb293356407330cfcd23e38229c35a6d7875697dfb293356407330cfcd23e
linuxlinux>= cff834c16d23d614388aab1b86d19eb67b3f80c4 < bbb7f49839b57d66ccaf7b5752d9b63d3031dd0abbb7f49839b57d66ccaf7b5752d9b63d3031dd0a
linuxlinux>= cff834c16d23d614388aab1b86d19eb67b3f80c4 < f0c33e7d387ccbb6870e73a43c558fefede06614f0c33e7d387ccbb6870e73a43c558fefede06614
linuxlinux>= cff834c16d23d614388aab1b86d19eb67b3f80c4 < 16907219ad6763f401700e1b57b2da4f3e07f04716907219ad6763f401700e1b57b2da4f3e07f047
linuxlinux>= cff834c16d23d614388aab1b86d19eb67b3f80c4 < 929b69810eec132b284ffd19047a85d961df9e4d929b69810eec132b284ffd19047a85d961df9e4d
linuxlinux>= cff834c16d23d614388aab1b86d19eb67b3f80c4 < e6693595bd1b55af62d057a4136a89d5c2ddf0e9e6693595bd1b55af62d057a4136a89d5c2ddf0e9
linuxlinux>= cff834c16d23d614388aab1b86d19eb67b3f80c4 < c225d006a31949d673e646d585d9569bc28feeb9c225d006a31949d673e646d585d9569bc28feeb9
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 4.6 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.26.13.2
linuxlinux_kernel>= 6.2 < 6.6.766.6.76
linuxlinux_kernel>= 6.7 < 6.12.136.12.13

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.