CVE-2024-39478: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in subsequent operations.
Affected products
- Linux Linux Kernel: from 6.9, before 6.9.5 (fixed in 6.9.5)
Published 2024-07-05. Last modified 2026-09-02.