CVE-2024-26846 — Double Free in Linux
Severity
4.4MEDIUMNVD
OSV7.0OSV6.5OSV5.5
EPSS
0.0%
top 98.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 17
Latest updateJul 26
Description
In the Linux kernel, the following vulnerability has been resolved:
nvme-fc: do not wait in vain when unloading module
The module exit path has race between deleting all controllers and
freeing 'left over IDs'. To prevent double free a synchronization
between nvme_delete_ctrl and ida_destroy has been added by the initial
commit.
There is some logic around trying to prevent from hanging forever in
wait_for_completion, though it does not handling all cases. E.g.
blktests is able to reproduce th…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6
Affected Packages5 packages
▶CVEListV5linux/linux4c73cbdff1119d088ed16d63def59ad32b11b18f — 4f2c95015ec2a1899161be6c0bdaecedd5a7bfb2+6
Also affects: Debian Linux 10.0