CVE-2024-57904: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91: call input_free_device() on allocated iio_dev Current implementation of at91_ts_register() calls input_free_deivce() on st->ts_input, however, the err label can be reached before the allocated iio_dev is stored to st->ts_input. Thus call input_free_device() on input instead of st->ts_input.

Affected products

  • Linux Linux Kernel: from 3.16, before 5.4.290 (fixed in 5.4.290); from 5.5, before 5.10.234 (fixed in 5.10.234); from 5.11, before 5.15.177 (fixed in 5.15.177); from 5.16, before 6.1.125 (fixed in 6.1.125); from 6.2, before 6.6.72 (fixed in 6.6.72); from 6.7, before 6.12.10 (fixed in 6.12.10); …

Published 2025-01-19. Last modified 2026-06-17.