CVE Database
/

CVE-2024-50152

Back to search

CVE-2024-50152

Published: Nov 7, 2024

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix possible double free in smb2_set_ea() Clang static checker(scan-build) warning: fs/smb/client/smb2ops.c:1304:2: Attempt to free released memory. 1304 | kfree(ea); | ^~~~~~~~~ There is a double free in such case: 'ea is initialized to NULL' -> 'first successful memory allocation for ea' -> 'something failed, goto sea_exit' -> 'first memory release for ea' -> 'goto replay_again' -> 'second goto sea_exit before allocate memory for ea' -> 'second memory release for ea resulted in double free'. Re-initialie 'ea' to NULL near to the replay_again label, it can fix this double free problem.

VendorProductVersions

Linux

Linux

affected
433042a91f9373241307725b52de573933ffedbf - < b1813c220b76f60b1727984794377c4aa849d4c1
affected
4f1fffa2376922f3d1d506e49c0fd445b023a28e - < c9f758ecf2562dfdd4adf12c22921b5de8366123
affected
4f1fffa2376922f3d1d506e49c0fd445b023a28e - < 19ebc1e6cab334a8193398d4152deb76019b5d34
affected
6.6.32 - < 6.6.59

Linux

Linux

affected
6.8
unaffected
0 - < 6.8
unaffected
6.6.59 - <= 6.6.*
unaffected
6.11.6 - <= 6.11.*
unaffected
6.12 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now