CVE-2024-57887

Source
https://cve.org/CVERecord?id=CVE-2024-57887
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-57887.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-57887
Downstream
Related
Published
2025-01-15T13:05:39.933Z
Modified
2026-05-28T03:55:32.070056186Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm: adv7511: Fix use-after-free in adv7533_attach_dsi()
Details

In the Linux kernel, the following vulnerability has been resolved:

drm: adv7511: Fix use-after-free in adv7533attachdsi()

The hostnode pointer was assigned and freed in adv7533parsedt(), and later, adv7533attachdsi() uses the same. Fix this use-after-free issue by dropping ofnodeput() in adv7533parsedt() and calling ofnode_put() in error path of probe() and also in the remove().

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/57xxx/CVE-2024-57887.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1e4d58cd7f888522d16f221d628356befbb08468
Fixed
acec80d9f126cd3fa764bbe3d96bc0cb5cd2b087
Fixed
d208571943ffddc438a7ce533d5d0b9219806242
Fixed
1f49aaf55652580ae63ab83d67211fe6a55d83dc
Fixed
ca9d077350fa21897de8bf64cba23b198740aab5
Fixed
81adbd3ff21c1182e06aa02c6be0bfd9ea02d8e8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-57887.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.8.0
Fixed
5.10.234
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
6.1.125
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.70
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-57887.json"