cbcvebase.
CVE-2024-35828
published 2024-05-17

CVE-2024-35828: In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() In the for statement of…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() In the for statement of lbs_allocate_cmd_buffer(), if the allocation of cmdarray[i].cmdbuf fails, both cmdarray and cmdarray[i].cmdbuf needs to be freed. Otherwise, there will be memleaks in lbs_allocate_cmd_buffer().

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 876c9d3aeb989cf1961f2c228d309ba5dcfb1172 < 96481624fb5a6319079fb5059e46dbce43a9018696481624fb5a6319079fb5059e46dbce43a90186
linuxlinux>= 876c9d3aeb989cf1961f2c228d309ba5dcfb1172 < bea9573c795acec5614d4ac2dcc7b3b684cea5bfbea9573c795acec5614d4ac2dcc7b3b684cea5bf
linuxlinux>= 876c9d3aeb989cf1961f2c228d309ba5dcfb1172 < f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7
linuxlinux>= 876c9d3aeb989cf1961f2c228d309ba5dcfb1172 < e888c4461e109f7b93c3522afcbbaa5a8fdf29d2e888c4461e109f7b93c3522afcbbaa5a8fdf29d2
linuxlinux>= 876c9d3aeb989cf1961f2c228d309ba5dcfb1172 < 4d99d267da3415db2124029cb5a6d2d955ca43f94d99d267da3415db2124029cb5a6d2d955ca43f9
linuxlinux>= 876c9d3aeb989cf1961f2c228d309ba5dcfb1172 < da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3
linuxlinux>= 876c9d3aeb989cf1961f2c228d309ba5dcfb1172 < d219724d4b0ddb8ec7dfeaed5989f23edabaf591d219724d4b0ddb8ec7dfeaed5989f23edabaf591
linuxlinux>= 876c9d3aeb989cf1961f2c228d309ba5dcfb1172 < 8e243ac649c10922a6b4855170eaefe4c5b3faab8e243ac649c10922a6b4855170eaefe4c5b3faab
linuxlinux>= 876c9d3aeb989cf1961f2c228d309ba5dcfb1172 < 5f0e4aede01cb01fa633171f0533affd25328c3a5f0e4aede01cb01fa633171f0533affd25328c3a
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 2.6.22 < 4.19.3114.19.311
linuxlinux_kernel>= 4.20 < 5.4.2735.4.273
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.5 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.