CVE-2024-42069

In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix possible double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function adev_release calls kfree(madev). We shouldn't call kfree(madev) again in the error handling path. Set 'madev' to NULL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:33

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/1864b8224195d0e43ddb92a8151f54f6562090cc - Patch () https://git.kernel.org/stable/c/1864b8224195d0e43ddb92a8151f54f6562090cc - Patch
References () https://git.kernel.org/stable/c/3243e64eb4d897c3eeb48b2a7221ab5a95e1282a - Patch () https://git.kernel.org/stable/c/3243e64eb4d897c3eeb48b2a7221ab5a95e1282a - Patch
References () https://git.kernel.org/stable/c/ed45c0a0b662079d4c0e518014cc148c753979b4 - Patch () https://git.kernel.org/stable/c/ed45c0a0b662079d4c0e518014cc148c753979b4 - Patch

30 Jul 2024, 19:01

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: mana: corrige posible double free en la ruta de manejo de errores Cuando auxiliar_device_add() devuelve un error y luego llama a auxiliar_device_uninit(), la función de devolución de llamada adev_release llama a kfree(madev). No deberíamos volver a llamar a kfree(madev) en la ruta de manejo de errores. Establezca 'madev' en NULL.
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/1864b8224195d0e43ddb92a8151f54f6562090cc - () https://git.kernel.org/stable/c/1864b8224195d0e43ddb92a8151f54f6562090cc - Patch
References () https://git.kernel.org/stable/c/3243e64eb4d897c3eeb48b2a7221ab5a95e1282a - () https://git.kernel.org/stable/c/3243e64eb4d897c3eeb48b2a7221ab5a95e1282a - Patch
References () https://git.kernel.org/stable/c/ed45c0a0b662079d4c0e518014cc148c753979b4 - () https://git.kernel.org/stable/c/ed45c0a0b662079d4c0e518014cc148c753979b4 - Patch
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

29 Jul 2024, 16:21

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 16:15

Updated : 2024-11-21 09:33


NVD link : CVE-2024-42069

Mitre link : CVE-2024-42069

CVE.ORG link : CVE-2024-42069


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference