PT-2024-7586 · Linux+3 · Linux Kernel+3
Dan Carpenter
·
Published
2024-08-02
·
Updated
2025-07-18
·
CVE-2024-47732
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to a potential use after free bug in the crypto: iaa module of the Linux kernel. Specifically, the
free device compression mode(iaa device, device mode) function frees the device mode but it is passed to iaa compression modes[i]->free() later, resulting in a use after free. This bug is currently in dead code and does not implement the ->free() function, but the fix is in place for when it might be implemented in the future. The exploitation of this bug could potentially impact the confidentiality, integrity, and availability of protected information.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Suse
Ubuntu