cbcvebase.
CVE-2024-42138
published 2024-07-30

CVE-2024-42138: In the Linux kernel, the following vulnerability has been resolved: mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file In case…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved: mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file In case of invalid INI file mlxsw_linecard_types_init() deallocates memory but doesn't reset pointer to NULL and returns 0. In case of any error occurred after mlxsw_linecard_types_init() call, mlxsw_linecards_init() calls mlxsw_linecard_types_fini() which performs memory deallocation again. Add pointer reset to NULL. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= b217127e5e4ee0ecfce7c5f84cfe082238123bda < ab557f5cd993a3201b09593633d04b891263d5c0ab557f5cd993a3201b09593633d04b891263d5c0
linuxlinux>= b217127e5e4ee0ecfce7c5f84cfe082238123bda < f8b55a465b0e8a500179808166fe9420f5c091a1f8b55a465b0e8a500179808166fe9420f5c091a1
linuxlinux>= b217127e5e4ee0ecfce7c5f84cfe082238123bda < 9af7437669b72f804fc4269f487528dbbed142a29af7437669b72f804fc4269f487528dbbed142a2
linuxlinux>= b217127e5e4ee0ecfce7c5f84cfe082238123bda < 8ce34dccbe8fa7d2ef86f2d8e7db2a9b67cabfc38ce34dccbe8fa7d2ef86f2d8e7db2a9b67cabfc3
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.19 < 6.1.986.1.98
linuxlinux_kernel>= 6.2 < 6.6.396.6.39
linuxlinux_kernel>= 6.7 < 6.9.96.9.9

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.