Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-33619
HistoryJun 25, 2024 - 12:00 a.m.

CVE-2024-33619

2024-06-2500:00:00
ubuntu.com
ubuntu.com
linux kernel
efi libstub
vulnerability
resolved
coverity static analysis
security testing
synopsys
inc.

7.1 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

In the Linux kernel, the following vulnerability has been resolved:
efi: libstub: only free priv.runtime_map when allocated
priv.runtime_map is only allocated when efi_novamap is not set.
Otherwise, it is an uninitialized value. In the error path, it is freed
unconditionally. Avoid passing an uninitialized value to free_pool.
Free priv.runtime_map only when it was allocated.
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.

7.1 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

Related for UB:CVE-2024-33619