CVE-2024-25739: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes, and crash, because of a missing check for ubi->leb_size.
Affected products
- Linux Linux Kernel: up to and including 6.7.4
Published 2024-02-12. Last modified 2026-06-17.