CVE-2024-57979 is a use-after-free vulnerability in the Linux kernel Pulse Per Second (PPS) subsystem during PPS-source unregistration. The PPS device destruction path freed a PPS device containing an embedded character-device object immediately after removing that character device. However, file operations associated with character-device handles opened before removal could still be invoked. Those operations could consequently access the freed PPS device and its character-device state. The upstream correction removes the embedded character-device lifetime model, uses a registered character-device interface with PPS IDR-based minor mapping, and retains a device reference while the device remains visible to userspace.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity local Linux kernel use-after-free vulnerability in the PPS subsystem's device teardown/unregistration handling. It can lead to memory corruption and kernel panic when PPS devices are removed while previously opened character-device file operations remain active.
A locally exploitable vulnerability requiring low privileges, with high confidentiality, integrity, and availability impact according to the supplied CVSS v3 vector.
A use-after-free vulnerability in the Linux kernel PPS subsystem.
A vulnerability included in the OpenShift Container Platform 4.14.49 advisory; no further technical details are provided in this content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.