CVE-2024-36899: gpiolib: cdev: Fix use after free in lineinfo_changed_notify
Published May 30, 2024
·Updated
gpiolib: cdev: Fix use after free in lineinfochangednotify
Affected Software
17 affected componentsFixes available
Linux Linux kernel>=5.7<6.6.31
Linux Linux kernel>=6.7<6.8.10
Linux Linux kernel=6.9-rc1
Linux Linux kernel=6.9-rc2
Linux Linux kernel=6.9-rc3
Linux Linux kernel=6.9-rc4
Linux Linux kernel=6.9-rc5
Linux Linux kernel=6.9-rc6
Linux Linux kernel=6.9-rc7
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
redhat/kernel<6.6.31
6.6.31
redhat/kernel<6.8.10
6.8.10
redhat/kernel<6.9
6.9
Microsoft cbl2 kernel 5.15.182.1-1
Microsoft cbl2 kernel 5.15.182.1-1
Microsoft cbl2 kernel 5.15.179.1-1
Remediation
Event History
May 30, 2024
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 3, 2024
Data Sourced
via Red Hat·01:18 PM
DescriptionSeverityAffected Software
Aug 8, 2024
Data Sourced
via Launchpad·11:25 PM
Description
May 1, 2025
Data Sourced
via Ubuntu·12:28 AM
RemedyDescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·03:10 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·03:10 AM
Affected Software
Updated
via Microsoft·03:10 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-36899?
CVE-2024-36899 has been rated as a high severity vulnerability affecting the Linux kernel.
2
How do I fix CVE-2024-36899?
To fix CVE-2024-36899, update the affected Linux kernel versions to the latest recommended secure versions.
3
What versions of the Linux kernel are affected by CVE-2024-36899?
CVE-2024-36899 affects various versions of the Linux kernel, particularly versions prior to 6.6.31 and select others.
4
Is my system at risk if I am using an affected version of the Linux kernel regarding CVE-2024-36899?
Yes, if your system is running an affected version of the Linux kernel, it is at risk of exploitation due to CVE-2024-36899.
5
What components of the Linux kernel are impacted by CVE-2024-36899?
CVE-2024-36899 impacts the gpiolib subsystem, specifically an issue caused by a use-after-free condition.