Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2024-42138
HistoryJul 30, 2024 - 7:46 a.m.

CVE-2024-42138 mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file

2024-07-3007:46:32
Linux
github.com
1
linux kernel
mlxsw
memory deallocation
vulnerability
ini file
error
pointer reset
linux verification center

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file

In case of invalid INI file mlxsw_linecard_types_init() deallocates memory
but doesn’t reset pointer to NULL and returns 0. In case of any error
occurred after mlxsw_linecard_types_init() call, mlxsw_linecards_init()
calls mlxsw_linecard_types_fini() which performs memory deallocation again.

Add pointer reset to NULL.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial