CVE-2024-42280: mISDN: Fix a use after free in hfcmulti_tx()
In the Linux kernel, the following vulnerability has been resolved:
mISDN: Fix a use after free in hfcmultitx()
Don't dereference sp after calling devkfreeskb(sp).
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42280?
CVE-2024-42280 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-42280?
To fix CVE-2024-42280, update the Linux kernel to the latest version provided in the remediation list.
Which Linux kernel versions are affected by CVE-2024-42280?
CVE-2024-42280 affects various Linux kernel versions, including versions up to 5.10.223-1 and others as specified in the announcement.
What type of vulnerability is CVE-2024-42280?
CVE-2024-42280 is a use-after-free vulnerability within the mISDN subsystem of the Linux kernel.
Who is affected by CVE-2024-42280?
Users running affected versions of the Linux kernel, particularly those utilizing the mISDN feature, are at risk from CVE-2024-42280.