cbcvebase.
CVE-2024-35972
published 2024-05-20

CVE-2024-35972: In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix possible memory leak in bnxt_rdma_aux_device_init() If ulp = kzalloc() fails…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix possible memory leak in bnxt_rdma_aux_device_init() If ulp = kzalloc() fails, the allocated edev will leak because it is not properly assigned and the cleanup path will not be able to free it. Fix it by assigning it properly immediately after allocation.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.8.9-1 (forky)linux 6.8.9-1 (forky)
linuxlinux
linuxlinux>= 30343221132430c24b468493c861f71e2bad131f < c60ed825530b8c0cc2b524efd39b1d696ec54004c60ed825530b8c0cc2b524efd39b1d696ec54004
linuxlinux>= 30343221132430c24b468493c861f71e2bad131f < 10a9d6a7513f93d7faffcb341af0aa42be8218fe10a9d6a7513f93d7faffcb341af0aa42be8218fe
linuxlinux>= 30343221132430c24b468493c861f71e2bad131f < 7ac10c7d728d75bc9daaa8fade3c7a3273b9a9ff7ac10c7d728d75bc9daaa8fade3c7a3273b9a9ff
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 5.11 < 5.15.1585.15.158
linuxlinux_kernel>= 5.16 < 6.1.876.1.87
linuxlinux_kernel>= 5.5 < 5.10.2165.10.216
linuxlinux_kernel>= 6.2 < 6.6.286.6.28
linuxlinux_kernel>= 6.7 < 6.8.76.8.7
msrcazl3_kernel_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_kernel_5.15.153.1-2_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.158.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.8MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.