Answer in brief
CVE-2024-49981 records a Unknown severity vulnerability in media: venus: fix use after free bug in venus_remove due to race condition. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-49981 records a Unknown severity vulnerability in media: venus: fix use after free bug in venus_remove due to race condition. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=af2c3834c8ca7cc65d15592ac671933df8848115 <5098b9e6377577fe13d03e1d8914930f014a3314 || >=af2c3834c8ca7cc65d15592ac671933df8848115 <63bbe26471ebdcc3c20bb4cc3950d666279ad658 || >=af2c3834c8ca7cc65d15592ac671933df8848115 <60b6968341a6dd5353554f3e72db554693a128a5 || >=af2c3834c8ca7cc65d15592ac671933df8848115 <bf6be32e2d39f6301ff1831e249d32a8744ab28a || >=af2c3834c8ca7cc65d15592ac671933df8848115 <2a541fcc0bd2b05a458e9613376df1289ec11621 || >=af2c3834c8ca7cc65d15592ac671933df8848115 <b0686aedc5f1343442d044bd64eeac7e7a391f4e || >=af2c3834c8ca7cc65d15592ac671933df8848115 <d925e9f7fb5a2dbefd1a73fc01061f38c7becd4c || >=af2c3834c8ca7cc65d15592ac671933df8848115 <10941d4f99a5a34999121b314afcd9c0a1c14f15 || >=af2c3834c8ca7cc65d15592ac671933df8848115 <c5a85ed88e043474161bbfe54002c89c1cb50ee2 | 5098b9e6377577fe13d03e1d8914930f014a3314, 63bbe26471ebdcc3c20bb4cc3950d666279ad658, 60b6968341a6dd5353554f3e72db554693a128a5, bf6be32e2d39f6301ff1831e249d32a8744ab28a, 2a541fcc0bd2b05a458e9613376df1289ec11621, b0686aedc5f1343442d044bd64eeac7e7a391f4e, d925e9f7fb5a2dbefd1a73fc01061f38c7becd4c, 10941d4f99a5a34999121b314afcd9c0a1c14f15, c5a85ed88e043474161bbfe54002c89c1cb50ee2 |
| Linux/Linuxgeneric | 4.13 | Not reported |
Published upstream
Oct 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: media: venus: fix use after free bug in venus_remove due to race condition in venus_probe, core->work is bound with venus_sys_error_handler, which is used to handle error. The code use core->sys_err_done to make sync work. The core->work is started in venus_event_notify. If we call venus_remove, there might be an unfished work. The possible sequence is as follows: CPU0 CPU1 |venus_sys_error_handler venus_remove | hfi_destroy | venus_hfi_destroy | kfree(hdev); | |hfi_reinit |venus_hfi_queues_reinit |//use hdev Fix it by canceling the work in venus_remove.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=af2c3834c8ca7cc65d15592ac671933df8848115 <5098b9e6377577fe13d03e1d8914930f014a3314 || >=af2c3834c8ca7cc65d15592ac671933df8848115 <63bbe26471ebdcc3c20bb4cc3950d666279ad658 || >=af2c3834c8ca7cc65d15592ac671933df8848115 <60b6968341a6dd5353554f3e72db554693a128a5 || >=af2c3834c8ca7cc65d15592ac671933df8848115 <bf6be32e2d39f6301ff1831e249d32a8744ab28a || >=af2c3834c8ca7cc65d15592ac671933df8848115 <2a541fcc0bd2b05a458e9613376df1289ec11621 || >=af2c3834c8ca7cc65d15592ac671933df8848115 <b0686aedc5f1343442d044bd64eeac7e7a391f4e || >=af2c3834c8ca7cc65d15592ac671933df8848115 <d925e9f7fb5a2dbefd1a73fc01061f38c7becd4c || >=af2c3834c8ca7cc65d15592ac671933df8848115 <10941d4f99a5a34999121b314afcd9c0a1c14f15 || >=af2c3834c8ca7cc65d15592ac671933df8848115 <c5a85ed88e043474161bbfe54002c89c1cb50ee2 | 5098b9e6377577fe13d03e1d8914930f014a3314, 63bbe26471ebdcc3c20bb4cc3950d666279ad658, 60b6968341a6dd5353554f3e72db554693a128a5, bf6be32e2d39f6301ff1831e249d32a8744ab28a, 2a541fcc0bd2b05a458e9613376df1289ec11621, b0686aedc5f1343442d044bd64eeac7e7a391f4e, d925e9f7fb5a2dbefd1a73fc01061f38c7becd4c, 10941d4f99a5a34999121b314afcd9c0a1c14f15, c5a85ed88e043474161bbfe54002c89c1cb50ee2 |
| Linux/Linuxgeneric | 4.13 | Not reported |
Published upstream
Oct 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: media: venus: fix use after free bug in venus_remove due to race condition in venus_probe, core->work is bound with venus_sys_error_handler, which is used to handle error. The code use core->sys_err_done to make sync work. The core->work is started in venus_event_notify. If we call venus_remove, there might be an unfished work. The possible sequence is as follows: CPU0 CPU1 |venus_sys_error_handler venus_remove | hfi_destroy | venus_hfi_destroy | kfree(hdev); | |hfi_reinit |venus_hfi_queues_reinit |//use hdev Fix it by canceling the work in venus_remove.
Quoted source text, attributed separately from HOL analysis.