CVE-2024-26652

In the Linux kernel, the following vulnerability has been resolved: net: pds_core: Fix possible double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), Callback function pdsc_auxbus_dev_release calls kfree(padev) to free memory. We shouldn't call kfree(padev) again in the error handling path. Fix this by cleaning up the redundant kfree() and putting the error handling back to where the errors happened.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc5:*:*:*:*:*:*

History

08 Apr 2025, 19:29

Type Values Removed Values Added
CWE CWE-415
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/ffda0e962f270b3ec937660afd15b685263232d3 - () https://git.kernel.org/stable/c/ffda0e962f270b3ec937660afd15b685263232d3 - Patch
References () https://git.kernel.org/stable/c/ba18deddd6d502da71fd6b6143c53042271b82bd - () https://git.kernel.org/stable/c/ba18deddd6d502da71fd6b6143c53042271b82bd - Patch
References () https://git.kernel.org/stable/c/995f802abff209514ac2ee03b96224237646cec3 - () https://git.kernel.org/stable/c/995f802abff209514ac2ee03b96224237646cec3 - Patch
CPE cpe:2.3:o:linux:linux_kernel:6.8:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*

27 Mar 2024, 15:49

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-27 14:15

Updated : 2025-04-08 19:29


NVD link : CVE-2024-26652

Mitre link : CVE-2024-26652


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-415

Double Free