CVE-2024-42069: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix possible double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function adev_release calls kfree(madev). We shouldn't call kfree(madev) again in the error handling path. Set 'madev' to NULL.

Affected products

  • Linux Linux Kernel: before 6.2 (fixed in 6.2); from 6.3, before 6.6.37 (fixed in 6.6.37); from 6.7, before 6.9.8 (fixed in 6.9.8)

Published 2024-07-29. Last modified 2026-08-04.