CVE-2024-39478: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in subsequent operations.

Affected products

  • Linux Linux Kernel: from 6.9, before 6.9.5 (fixed in 6.9.5)

Published 2024-07-05. Last modified 2026-09-02.