ZeroHour

CVE-2024-39478

CVSS 3.1
5.5 medium
EPSS
<1%p13
Published
()
Modified
Description

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in subsequent operations.

Vendors
linux
Products
linux kernel
Weakness
CWE-770
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.