CVE-2024-49992
Published: Oct 21, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: drm/stm: Avoid use-after-free issues with crtc and plane ltdc_load() calls functions drm_crtc_init_with_planes(), drm_universal_plane_init() and drm_encoder_init(). These functions should not be called with parameters allocated with devm_kzalloc() to avoid use-after-free issues [1]. Use allocations managed by the DRM framework. Found by Linux Verification Center (linuxtesting.org). [1] https://lore.kernel.org/lkml/u366i76e3qhh3ra5oxrtngjtm2u5lterkekcz6y2jkndhuxzli@diujon4h7qwb/
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected b759012c5fa761ee08998c80fc4ad6343c258487 - < d02611ff001454358be6910cb926799e2d818716affected b759012c5fa761ee08998c80fc4ad6343c258487 - < 0a1741d10da29aa84955ef89ae9a03c4b6038657affected b759012c5fa761ee08998c80fc4ad6343c258487 - < 454e5d7e671946698af0f201e48469e5ddb42851affected b759012c5fa761ee08998c80fc4ad6343c258487 - < b22eec4b57d04befa90e8554ede34e6c67257606affected b759012c5fa761ee08998c80fc4ad6343c258487 - < 19dd9780b7ac673be95bf6fd6892a184c9db611f |
Linux | Linux | affected 4.13unaffected 0 - < 4.13unaffected 6.1.113 - <= 6.1.*unaffected 6.6.55 - <= 6.6.*unaffected 6.10.14 - <= 6.10.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now