CVE-2024-27413: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: efi/capsule-loader: fix incorrect allocation size gcc-14 notices that the allocation with sizeof(void) on 32-bit architectures is not enough for a 64-bit phys_addr_t: drivers/firmware/efi/capsule-loader.c: In function 'efi_capsule_open': drivers/firmware/efi/capsule-loader.c:295:24: error: allocation of insufficient size '4' for type 'phys_addr_t' {aka 'long long unsigned int'} with size '8' [-Werror=alloc-size] 295 | cap_info->phys = kzalloc(sizeof(void *), GFP_KERNEL); | ^ Use the correct type instead here.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 4.14.13, before 4.15 (fixed in 4.15); from 4.15.1, before 4.19.309 (fixed in 4.19.309); from 4.20, before 5.4.271 (fixed in 5.4.271); from 5.5, before 5.10.212 (fixed in 5.10.212); from 5.11, before 5.15.151 (fixed in 5.15.151); from 5.16, before 6.1.81 (fixed in 6.1.81); …

Published 2024-05-17. Last modified 2026-06-17.