CVE-2024-50028
MEDIUM EPSS 10.5%
Published Oct 21, 20241y ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Published Oct 21, 2024 1y ago
Last Modified Jun 17, 2026 2w ago
Description
In the Linux kernel, the following vulnerability has been resolved: thermal: core: Reference count the zone in thermal_zone_get_by_id() There are places in the thermal netlink code where nothing prevents the thermal zone object from going away while being accessed after it has been returned by thermal_zone_get_by_id(). To address this, make thermal_zone_get_by_id() get a reference on the thermal zone device object to be returned with the help of get_device(), under thermal_list_lock, and adjust all of its callers to this change with the help of the cleanup.h infrastructure.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
10.5% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Affected Products 3
References 2
- git.kernel.org https://git.kernel.org/stable/c/a42a5839f400e929c489bb1b58f54596c4535167
- git.kernel.org https://git.kernel.org/stable/c/c95538b286efc6109c987e97a051bc7844ede802
Remediation
- git.kernel.org https://git.kernel.org/stable/c/a42a5839f400e929c489bb1b58f54596c4535167
- git.kernel.org https://git.kernel.org/stable/c/c95538b286efc6109c987e97a051bc7844ede802