cbcvebase.
CVE-2024-36973
published 2024-06-17

CVE-2024-36973: In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe() When…

PriorityP434high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe() When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function gp_auxiliary_device_release() calls ida_free() and kfree(aux_device_wrapper) to free memory. We should't call them again in the error handling path. Fix this by skipping the redundant cleanup functions.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 393fc2f5948fd340d016a9557eea6e1ac2f6c60c < 34ae447b138680b5ed3660f7d935ff3faf88ba1a34ae447b138680b5ed3660f7d935ff3faf88ba1a
linuxlinux>= 393fc2f5948fd340d016a9557eea6e1ac2f6c60c < 86c9713602f786f441630c4ee02891987f8618b986c9713602f786f441630c4ee02891987f8618b9
linuxlinux>= 393fc2f5948fd340d016a9557eea6e1ac2f6c60c < 1efe551982297924d05a367aa2b6ec3d275d57421efe551982297924d05a367aa2b6ec3d275d5742
linuxlinux>= 393fc2f5948fd340d016a9557eea6e1ac2f6c60c < 086c6cbcc563c81d55257f9b27e14faf1d0963d3086c6cbcc563c81d55257f9b27e14faf1d0963d3
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.1 < 6.1.956.1.95
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.