CVE-2024-36899: gpiolib: cdev: Fix use after free in lineinfo_changed_notify
gpiolib: cdev: Fix use after free in lineinfochangednotify
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.31 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8.10 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch CVE-2024-36899
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36899?
CVE-2024-36899 has been rated as a high severity vulnerability affecting the Linux kernel.
How do I fix CVE-2024-36899?
To fix CVE-2024-36899, update the affected Linux kernel versions to the latest recommended secure versions.
What versions of the Linux kernel are affected by CVE-2024-36899?
CVE-2024-36899 affects various versions of the Linux kernel, particularly versions prior to 6.6.31 and select others.
Is my system at risk if I am using an affected version of the Linux kernel regarding CVE-2024-36899?
Yes, if your system is running an affected version of the Linux kernel, it is at risk of exploitation due to CVE-2024-36899.
What components of the Linux kernel are impacted by CVE-2024-36899?
CVE-2024-36899 impacts the gpiolib subsystem, specifically an issue caused by a use-after-free condition.