CVE-2024-36959: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() If we fail to allocate propname buffer, we need to drop the reference count we just took. Because the pinctrl_dt_free_maps() includes the droping operation, here we call it directly.

Affected products

  • Linux Linux Kernel: from 4.9.334, before 4.10 (fixed in 4.10); from 4.14.300, before 4.15 (fixed in 4.15); from 4.19.267, before 4.19.314 (fixed in 4.19.314); from 5.4.225, before 5.4.276 (fixed in 5.4.276); from 5.10.156, before 5.10.217 (fixed in 5.10.217); from 5.15.80, before 5.15.159 (fixed in 5.15.159); …

Published 2024-05-30. Last modified 2026-06-17.