CVE-2024-50027

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
21/10/2024
Last modified:
08/11/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> thermal: core: Free tzp copy along with the thermal zone<br /> <br /> The object pointed to by tz-&gt;tzp may still be accessed after being<br /> freed in thermal_zone_device_unregister(), so move the freeing of it<br /> to the point after the removal completion has been completed at which<br /> it cannot be accessed any more.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.4 (including) 6.11.4 (including)
cpe:2.3:o:linux:linux_kernel:6.12:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc2:*:*:*:*:*:*