Cyber Resilience

CVE-2024-57872

Linux Kernel 3.10 – 6.12.5

Published
11 January 2025
Modified
01 October 2025
Patch / advisory
CVSS Score v3.1 5.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0018 7th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2024-57872 is a medium-severity Missing Release of Memory after Effective Lifetime (CWE-401) vulnerability in Linux Linux Kernel. Its CVSS base score is 5.5 (Medium).

Operationally, ranked at the 7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: pltfrm: Dellocate HBA during ufshcd_pltfrm_remove() This will ensure that the scsi host is cleaned up properly using scsi_host_dev_release(). Otherwise, it may lead to memory leaks.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-56712Same product: Linux Linux Kernel
CVE-2023-52702Same product: Linux Linux Kernel
CVE-2023-53441Same product: Linux Linux Kernel
CVE-2026-53127Same product: Linux Linux Kernel
CVE-2023-53299Same product: Linux Linux Kernel
CVE-2024-50041Same product: Linux Linux Kernel
CVE-2024-42262Same product: Linux Linux Kernel
CVE-2023-53562Same product: Linux Linux Kernel
CVE-2024-43913Same product: Linux Linux Kernel
CVE-2026-23061Same product: Linux Linux Kernel

Affected Assets

linux
linux kernel
6.13 · 3.10 — 6.12.5

Mitigating Controls

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly enforce proper memory allocation/deallocation via coding standards, reviews, and tooling.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

detects

Security testing in development can detect unreleased memory, providing partial coverage of the weakness.

prevents

Secure development life cycle mandates memory-management practices that reduce missing-release defects.

prevents

Application security requirements can specify explicit memory-release rules, partially mitigating the weakness.

prevents

Secure system architecture and engineering principles include resource-management guidelines that address memory leaks.

prevents

Secure coding standards directly require proper allocation/deallocation, covering most of this weakness.

detects

Capacity management may detect memory exhaustion symptoms but does not prevent the coding flaw.

References