CVE-2024-39478
Executive Summary
CVE-2024-39478: In the Linux kernel's StarFive crypto module, a stack‑allocated buffer used for RSA text data was incorrectly freed with kfree, causing undefined behavior and potential memory corruption. The issue has been fixed; no known exploitation or CISA KEV listing.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2024-07-05T07:15:10.470 - Last Modified: 2026-09-02T13:16:47.893
Original Description: In the Linux kernel, the following vulnerability has been resolved:
crypto: starfive - Do not free stack buffer
RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in subsequent operations.
"Every person, all the events of your life are there because you have drawn them there. What you choose to do with them is up to you."
— Richard Bach