CVE-2024-56538

In the Linux kernel, the following vulnerability has been resolved: drm: zynqmp_kms: Unplug DRM device before removal Prevent userspace accesses to the DRM device from causing use-after-frees by unplugging the device before we remove it. This causes any further userspace accesses to result in an error without further calls into this driver's internals.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

14 Jan 2025, 17:21

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: drm: zynqmp_kms: Desconectar el dispositivo DRM antes de quitarlo. Evite que los accesos al espacio de usuario del dispositivo DRM provoquen use-after-frees desconectando el dispositivo antes de quitarlo. Esto hace que cualquier otro acceso al espacio de usuario genere un error sin más llamadas a los componentes internos de este controlador.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-416
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/2e07c88914fc5289c21820b1aa94f058feb38197 - () https://git.kernel.org/stable/c/2e07c88914fc5289c21820b1aa94f058feb38197 - Patch
References () https://git.kernel.org/stable/c/4fb97432e28a7e136b2d76135d50e988ada8e1af - () https://git.kernel.org/stable/c/4fb97432e28a7e136b2d76135d50e988ada8e1af - Patch
References () https://git.kernel.org/stable/c/692f52aedccbf79b212a1e14e3735192b4c24a7d - () https://git.kernel.org/stable/c/692f52aedccbf79b212a1e14e3735192b4c24a7d - Patch
References () https://git.kernel.org/stable/c/a17b9afe58c474657449cf87e238b1788200576b - () https://git.kernel.org/stable/c/a17b9afe58c474657449cf87e238b1788200576b - Patch

27 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-27 14:15

Updated : 2025-02-11 16:15


NVD link : CVE-2024-56538

Mitre link : CVE-2024-56538

CVE.ORG link : CVE-2024-56538


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free