CVE-2024-49992

Source
https://cve.org/CVERecord?id=CVE-2024-49992
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-49992.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-49992
Downstream
Related
Published
2024-10-21T18:02:34.442Z
Modified
2026-05-28T03:53:43.229088470Z
Summary
drm/stm: Avoid use-after-free issues with crtc and plane
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/stm: Avoid use-after-free issues with crtc and plane

ltdcload() calls functions drmcrtcinitwithplanes(), drmuniversalplaneinit() and drmencoderinit(). These functions should not be called with parameters allocated with devm_kzalloc() to avoid use-after-free issues [1].

Use allocations managed by the DRM framework.

Found by Linux Verification Center (linuxtesting.org).

[1] https://lore.kernel.org/lkml/u366i76e3qhh3ra5oxrtngjtm2u5lterkekcz6y2jkndhuxzli@diujon4h7qwb/

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/49xxx/CVE-2024-49992.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b759012c5fa761ee08998c80fc4ad6343c258487
Fixed
d02611ff001454358be6910cb926799e2d818716
Fixed
0a1741d10da29aa84955ef89ae9a03c4b6038657
Fixed
454e5d7e671946698af0f201e48469e5ddb42851
Fixed
b22eec4b57d04befa90e8554ede34e6c67257606
Fixed
19dd9780b7ac673be95bf6fd6892a184c9db611f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-49992.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.13.0
Fixed
6.1.113
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.55
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.10.14
Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.11.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-49992.json"