CVE-2024-27039

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-27039
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-27039.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-27039
Downstream
Related
Published
2024-05-01T12:53:57.126Z
Modified
2025-11-28T02:35:52.082198Z
Summary
clk: hisilicon: hi3559a: Fix an erroneous devm_kfree()
Details

In the Linux kernel, the following vulnerability has been resolved:

clk: hisilicon: hi3559a: Fix an erroneous devm_kfree()

'p_clk' is an array allocated just before the for loop for all clk that need to be registered. It is incremented at each loop iteration.

If a clkregister() call fails, 'pclk' may point to something different from what should be freed.

The best we can do, is to avoid this wrong release of memory.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27039.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6c81966107dc0caa5d2ebedbcebb5f10d865064d
Fixed
3f8445f1c746fda180a7f75372ed06b24e9cefe2
Fixed
e0b0d1c46a2ce1e46b79d004a7270fdef872e097
Fixed
95d1f1228c1bb54803ae57525b76db60e99b37e4
Fixed
2cc572e0085ebd4b662b74a0f43222bc00df9a00
Fixed
d575765b1b62e8bdb00af11caa1aabeb01763d9f
Fixed
64c6a38136b74a2f18c42199830975edd9fbc379

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
5.15.153
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.83
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.23
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.11
Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.8.2