CVE-2024-0217: Fedoraproject Fedora
Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.
Affected products
- Fedoraproject Fedora: version 39 only
- Packagekit Project Packagekit: before 1.2.7 (fixed in 1.2.7)
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
Published 2024-01-03. Last modified 2026-06-17.