In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: fix wrong use of sizeof in cmdq_get_clocks() It should be size of the struct clk_bulk_data, not data pointer pass to devm_kcalloc().
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024122833-CVE-2024-56684-55a3@gregkh/T