CVE-2024-36030 is a double free vulnerability in the Linux kernel's octeontx2-af driver, specifically within the rvu_npc_freemem() function. This flaw, identified by Clang static checker, affects Linux kernel versions and could lead to a denial of service or potentially information disclosure. Rated High with a CVSS score of 7.1, it requires local access and low privileges to exploit, with a high impact on availability and potential for confidentiality compromise. Currently, there is no public exploit code available, nor any evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.8, < 6.8.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:* | ||
6.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:* | ||
6.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:* | ||
6.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.