CVE Database
/

CVE-2024-49992

Back to search

CVE-2024-49992

Published: Oct 21, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: drm/stm: Avoid use-after-free issues with crtc and plane ltdc_load() calls functions drm_crtc_init_with_planes(), drm_universal_plane_init() and drm_encoder_init(). These functions should not be called with parameters allocated with devm_kzalloc() to avoid use-after-free issues [1]. Use allocations managed by the DRM framework. Found by Linux Verification Center (linuxtesting.org). [1] https://lore.kernel.org/lkml/u366i76e3qhh3ra5oxrtngjtm2u5lterkekcz6y2jkndhuxzli@diujon4h7qwb/

VendorProductVersions

Linux

Linux

affected
b759012c5fa761ee08998c80fc4ad6343c258487 - < d02611ff001454358be6910cb926799e2d818716
affected
b759012c5fa761ee08998c80fc4ad6343c258487 - < 0a1741d10da29aa84955ef89ae9a03c4b6038657
affected
b759012c5fa761ee08998c80fc4ad6343c258487 - < 454e5d7e671946698af0f201e48469e5ddb42851
affected
b759012c5fa761ee08998c80fc4ad6343c258487 - < b22eec4b57d04befa90e8554ede34e6c67257606
affected
b759012c5fa761ee08998c80fc4ad6343c258487 - < 19dd9780b7ac673be95bf6fd6892a184c9db611f

Linux

Linux

affected
4.13
unaffected
0 - < 4.13
unaffected
6.1.113 - <= 6.1.*
unaffected
6.6.55 - <= 6.6.*
unaffected
6.10.14 - <= 6.10.*

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now