In the Linux kernel, the following vulnerability has been resolved:
Drivers: hv: vmbus: Use after free in __vmbus_open()
The “open_info” variable is added to the &vmbus_connection.chn_msg_list,
but the error handling frees “open_info” without removing it from the
list. This will result in a use after free. First remove it from the
list, and then free it.
[
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6f3d791f3006",
"lessThan": "d5c7b42c9f56",
"versionType": "git"
},
{
"status": "affected",
"version": "6f3d791f3006",
"lessThan": "f37dd5d1b5d3",
"versionType": "git"
},
{
"status": "affected",
"version": "6f3d791f3006",
"lessThan": "2728f289b327",
"versionType": "git"
},
{
"status": "affected",
"version": "6f3d791f3006",
"lessThan": "3e9bf43f7f7a",
"versionType": "git"
}
],
"programFiles": [
"drivers/hv/channel.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.14"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.14",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "5.10.37",
"versionType": "custom",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.11.21",
"versionType": "custom",
"lessThanOrEqual": "5.11.*"
},
{
"status": "unaffected",
"version": "5.12.4",
"versionType": "custom",
"lessThanOrEqual": "5.12.*"
},
{
"status": "unaffected",
"version": "5.13",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/hv/channel.c"
],
"defaultStatus": "affected"
}
]