CVE-2024-36973
Linux Linux, linux kernel
In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe() When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function gp_auxiliary_device_release() calls ida_free() and kfree(aux_device_wrapper) to free memory. We should't call them again in the error handling path. Fix this by skipping the redundant cleanup functions.
- CVSS
- 7.8
- EPSS
- 0.24% 14.9% percentile
- CISA KEV
- Not listed
- Published
- 2024.06.18