Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-42138
HistoryJul 30, 2024 - 12:00 a.m.

CVE-2024-42138

2024-07-3000:00:00
ubuntu.com
ubuntu.com
3
linux kernel vulnerability mlxsw linecards memory deallocation svace.ini file error mitigation

AI Score

7

Confidence

Low

In the Linux kernel, the following vulnerability has been resolved:
mlxsw: core_linecards: Fix double memory deallocation in case of invalid
INI file
In case of invalid INI file mlxsw_linecard_types_init() deallocates memory
but doesn’t reset pointer to NULL and returns 0. In case of any error
occurred after mlxsw_linecard_types_init() call, mlxsw_linecards_init()
calls mlxsw_linecard_types_fini() which performs memory deallocation again.
Add pointer reset to NULL.
Found by Linux Verification Center (linuxtesting.org) with SVACE.