CVE-2024-42069: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix possible double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function adev_release calls kfree(madev). We shouldn't call kfree(madev) again in the error handling path. Set 'madev' to NULL.
Affected products
- Linux Linux Kernel: before 6.2 (fixed in 6.2); from 6.3, before 6.6.37 (fixed in 6.6.37); from 6.7, before 6.9.8 (fixed in 6.9.8)
Published 2024-07-29. Last modified 2026-08-04.