CVE-2024-43900

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
26/08/2024
Last modified:
03/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> media: xc2028: avoid use-after-free in load_firmware_cb()<br /> <br /> syzkaller reported use-after-free in load_firmware_cb() [1].<br /> The reason is because the module allocated a struct tuner in tuner_probe(),<br /> and then the module initialization failed, the struct tuner was released.<br /> A worker which created during module initialization accesses this struct<br /> tuner later, it caused use-after-free.<br /> <br /> The process is as follows:<br /> <br /> task-6504 worker_thread<br /> tuner_probe

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.105 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.46 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.10.5 (excluding)