CVE-2024-26652

In the Linux kernel, the following vulnerability has been resolved: net: pds_core: Fix possible double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), Callback function pdsc_auxbus_dev_release calls kfree(padev) to free memory. We shouldn't call kfree(padev) again in the error handling path. Fix this by cleaning up the redundant kfree() and putting the error handling back to where the errors happened.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc6:*:*:*:*:*:*

History

08 Apr 2025, 19:29

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CWE CWE-415
CPE cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/995f802abff209514ac2ee03b96224237646cec3 - () https://git.kernel.org/stable/c/995f802abff209514ac2ee03b96224237646cec3 - Patch
References () https://git.kernel.org/stable/c/ba18deddd6d502da71fd6b6143c53042271b82bd - () https://git.kernel.org/stable/c/ba18deddd6d502da71fd6b6143c53042271b82bd - Patch
References () https://git.kernel.org/stable/c/ffda0e962f270b3ec937660afd15b685263232d3 - () https://git.kernel.org/stable/c/ffda0e962f270b3ec937660afd15b685263232d3 - Patch

Information

Published : 2024-03-27 14:15

Updated : 2025-04-08 19:29


NVD link : CVE-2024-26652

Mitre link : CVE-2024-26652

CVE.ORG link : CVE-2024-26652


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-415

Double Free