PT-2024-4320 · Linux+4 · Linux Kernel+4

Dave Jiang

+2

·

Published

2024-05-04

·

Updated

2025-09-29

·

CVE-2024-38629

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the unnecessary destruction of file ida in the Linux kernel, specifically in the dmaengine subsystem. This can lead to accessing an id in file ida after it has been destroyed, resulting in a kernel panic. The problem occurs because ida free() in cdev release may happen after the destruction of file ida per WQ cdev.
Recommendations To address this issue, remove the ida destroy(&file ida) call to prevent unnecessary destruction of file ida. Update to a version of the Linux kernel that includes this fix, such as version 6.6.37 or later.

Exploit

Fix

Improper Resource Release

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-04808
CVE-2024-38629
INFSA-2024_9315
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1836
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7008-1
USN-7029-1

Affected Products

Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu