CVE-2024-33619
In the Linux kernel, the following vulnerability has been resolved: efi: libstub: only free priv.runtime_map when allocated priv.runtime_m
CVSS
7.8
High
EPSS
0.3%
p16
KEV
—
Exploit Today
5
0-100
Published: Jun 21, 2024 · Last modified: Aug 4, 2026 · CWE-908
0.2%EPSS · 30 days0.3%
2026-07-312026-08-28
In the Linux kernel, the following vulnerability has been resolved: efi: libstub: only free priv.runtime_map when allocated priv.runtime_map is only allocated when efi_novamap is not set. Otherwise, it is an uninitialized value. In the error path, it is freed unconditionally. Avoid passing an uninitialized value to free_pool. Free priv.runtime_map only when it was allocated. This bug was discovered and resolved using Coverity Static Analysis Security Testing (SAST) by Synopsys, Inc.
- git.kernel.orghttps://git.kernel.org/stable/c/4b2543f7e1e6b91cfc8dd1696e3cdf01c3ac8974
- git.kernel.orghttps://git.kernel.org/stable/c/6ca67a5fe1c606d1fbe24c30a9fc0bdc43a18554
- git.kernel.orghttps://git.kernel.org/stable/c/9dce01f386c9ce6990c0a83fa14b1c95330b037e
- git.kernel.orghttps://git.kernel.org/stable/c/b8938d6f570f010a1dcdbfed3e5b5d3258c2a908
- git.kernel.orghttps://git.kernel.org/stable/c/4b2543f7e1e6b91cfc8dd1696e3cdf01c3ac8974
- git.kernel.orghttps://git.kernel.org/stable/c/6ca67a5fe1c606d1fbe24c30a9fc0bdc43a18554
- git.kernel.orghttps://git.kernel.org/stable/c/9dce01f386c9ce6990c0a83fa14b1c95330b037e
- git.kernel.orghttps://git.kernel.org/stable/c/b8938d6f570f010a1dcdbfed3e5b5d3258c2a908
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-792856.5 MED21.1%
——6Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-792706.5 MED21.1%
——6Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-792694.3 MED16.9%
——5Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)2dCVE-2026-792296.5 MED21.1%
——6Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-792216.5 MED8.7%
——3Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-791206.5 MED15.4%
——5Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)1d