CVE-2024-49853

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix double free in OPTEE transport Channels can be shared between protocols, avoid freeing the same channel descriptors twice when unloading the stack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Oct 2024, 16:14

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/6699567b0bbb378600a4dc0a1f929439a4e84a2c - () https://git.kernel.org/stable/c/6699567b0bbb378600a4dc0a1f929439a4e84a2c - Patch
References () https://git.kernel.org/stable/c/aef6ae124bb3cc12e34430fed91fbb7efd7a444d - () https://git.kernel.org/stable/c/aef6ae124bb3cc12e34430fed91fbb7efd7a444d - Patch
References () https://git.kernel.org/stable/c/d7f4fc2bc101e666da649605a9ece2bd42529c7a - () https://git.kernel.org/stable/c/d7f4fc2bc101e666da649605a9ece2bd42529c7a - Patch
References () https://git.kernel.org/stable/c/dc9543a4f2a5498a4a12d6d2427492a6f1a28056 - () https://git.kernel.org/stable/c/dc9543a4f2a5498a4a12d6d2427492a6f1a28056 - Patch
References () https://git.kernel.org/stable/c/e98dba934b2fc587eafb83f47ad64d9053b18ae0 - () https://git.kernel.org/stable/c/e98dba934b2fc587eafb83f47ad64d9053b18ae0 - Patch
CWE CWE-415
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: firmware: arm_scmi: Corrección de doble liberación en el transporte OPTEE Los canales se pueden compartir entre protocolos, evitando liberar los mismos descriptores de canal dos veces al descargar la pila.
First Time Linux linux Kernel
Linux

21 Oct 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-21 13:15

Updated : 2024-10-23 16:14


NVD link : CVE-2024-49853

Mitre link : CVE-2024-49853

CVE.ORG link : CVE-2024-49853


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-415

Double Free