cbcvebase.
CVE-2024-58063
published 2025-03-06

CVE-2024-58063: In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: fix memory leaks and invalid access at probe error path Deinitialize at…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.1th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: fix memory leaks and invalid access at probe error path Deinitialize at reverse order when probe fails. When init_sw_vars fails, rtl_deinit_core should not be called, specially now that it destroys the rtl_wq workqueue. And call rtl_pci_deinit and deinit_sw_vars, otherwise, memory will be leaked. Remove pci_set_drvdata call as it will already be cleaned up by the core driver code and could lead to memory leaks too. cf. commit 8d450935ae7f ("wireless: rtlwifi: remove unnecessary pci_set_drvdata()") and commit 3d86b93064c7 ("rtlwifi: Fix PCI probe error path orphaned memory").

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= 0c8173385e549f95cd80c3fff5aab87b4f881d8d < 85b67b4c4a0f8a6fb20cf4ef7684ff2b0cf559df85b67b4c4a0f8a6fb20cf4ef7684ff2b0cf559df
linuxlinux>= 0c8173385e549f95cd80c3fff5aab87b4f881d8d < 455e0f40b5352186a9095f2135d5c89255e7c39a455e0f40b5352186a9095f2135d5c89255e7c39a
linuxlinux>= 0c8173385e549f95cd80c3fff5aab87b4f881d8d < b96371339fd9cac90f5ee4ac17ee5c4cbbdfa6f7b96371339fd9cac90f5ee4ac17ee5c4cbbdfa6f7
linuxlinux>= 0c8173385e549f95cd80c3fff5aab87b4f881d8d < ee0b0d7baa8a6d42c7988f6e50c8f164cdf3fa47ee0b0d7baa8a6d42c7988f6e50c8f164cdf3fa47
linuxlinux>= 0c8173385e549f95cd80c3fff5aab87b4f881d8d < 624cea89a0865a2bc3e00182a6b0f954a94328b4624cea89a0865a2bc3e00182a6b0f954a94328b4
linuxlinux>= 0c8173385e549f95cd80c3fff5aab87b4f881d8d < 32acebca0a51f5e372536bfdc0d7d332ab74901332acebca0a51f5e372536bfdc0d7d332ab749013
linuxlinux>= 0c8173385e549f95cd80c3fff5aab87b4f881d8d < 6b76bab5c257463302c9e97f5d84d524457468eb6b76bab5c257463302c9e97f5d84d524457468eb
linuxlinux>= 0c8173385e549f95cd80c3fff5aab87b4f881d8d < e7ceefbfd8d447abc8aca8ab993a942803522c06e7ceefbfd8d447abc8aca8ab993a942803522c06
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 2.6.38 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.26.13.2
linuxlinux_kernel>= 6.2 < 6.6.766.6.76
linuxlinux_kernel>= 6.7 < 6.12.136.12.13

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.