Answer in brief
CVE-2024-49992 records a Unknown severity vulnerability in drm/stm: Avoid use-after-free issues with crtc and plane. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b759012c5fa761ee08998c80fc4ad6343c258487 <d02611ff001454358be6910cb926799e2d818716 || >=b759012c5fa761ee08998c80fc4ad6343c258487 <0a1741d10da29aa84955ef89ae9a03c4b6038657 || >=b759012c5fa761ee08998c80fc4ad6343c258487 <454e5d7e671946698af0f201e48469e5ddb42851 || >=b759012c5fa761ee08998c80fc4ad6343c258487 <b22eec4b57d04befa90e8554ede34e6c67257606 || >=b759012c5fa761ee08998c80fc4ad6343c258487 <19dd9780b7ac673be95bf6fd6892a184c9db611f | d02611ff001454358be6910cb926799e2d818716, 0a1741d10da29aa84955ef89ae9a03c4b6038657, 454e5d7e671946698af0f201e48469e5ddb42851, b22eec4b57d04befa90e8554ede34e6c67257606, 19dd9780b7ac673be95bf6fd6892a184c9db611f |
| Linux/Linuxgeneric | 4.13 | Not reported |
Published upstream
Oct 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/stm: Avoid use-after-free issues with crtc and plane ltdc_load() calls functions drm_crtc_init_with_planes(), drm_universal_plane_init() and drm_encoder_init(). These functions should not be called with parameters allocated with devm_kzalloc() to avoid use-after-free issues [1]. Use allocations managed by the DRM framework. Found by Linux Verification Center (linuxtesting.org). [1] https://lore.kernel.org/lkml/u366i76e3qhh3ra5oxrtngjtm2u5lterkekcz6y2jkndhuxzli@diujon4h7qwb/
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-49992 records a Unknown severity vulnerability in drm/stm: Avoid use-after-free issues with crtc and plane. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b759012c5fa761ee08998c80fc4ad6343c258487 <d02611ff001454358be6910cb926799e2d818716 || >=b759012c5fa761ee08998c80fc4ad6343c258487 <0a1741d10da29aa84955ef89ae9a03c4b6038657 || >=b759012c5fa761ee08998c80fc4ad6343c258487 <454e5d7e671946698af0f201e48469e5ddb42851 || >=b759012c5fa761ee08998c80fc4ad6343c258487 <b22eec4b57d04befa90e8554ede34e6c67257606 || >=b759012c5fa761ee08998c80fc4ad6343c258487 <19dd9780b7ac673be95bf6fd6892a184c9db611f | d02611ff001454358be6910cb926799e2d818716, 0a1741d10da29aa84955ef89ae9a03c4b6038657, 454e5d7e671946698af0f201e48469e5ddb42851, b22eec4b57d04befa90e8554ede34e6c67257606, 19dd9780b7ac673be95bf6fd6892a184c9db611f |
| Linux/Linuxgeneric | 4.13 | Not reported |
Published upstream
Oct 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/stm: Avoid use-after-free issues with crtc and plane ltdc_load() calls functions drm_crtc_init_with_planes(), drm_universal_plane_init() and drm_encoder_init(). These functions should not be called with parameters allocated with devm_kzalloc() to avoid use-after-free issues [1]. Use allocations managed by the DRM framework. Found by Linux Verification Center (linuxtesting.org). [1] https://lore.kernel.org/lkml/u366i76e3qhh3ra5oxrtngjtm2u5lterkekcz6y2jkndhuxzli@diujon4h7qwb/
Quoted source text, attributed separately from HOL analysis.