CVE-2024-50152
Published: Nov 7, 2024
Modified: May 23, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix possible double free in smb2_set_ea() Clang static checker(scan-build) warning: fs/smb/client/smb2ops.c:1304:2: Attempt to free released memory. 1304 | kfree(ea); | ^~~~~~~~~ There is a double free in such case: 'ea is initialized to NULL' -> 'first successful memory allocation for ea' -> 'something failed, goto sea_exit' -> 'first memory release for ea' -> 'goto replay_again' -> 'second goto sea_exit before allocate memory for ea' -> 'second memory release for ea resulted in double free'. Re-initialie 'ea' to NULL near to the replay_again label, it can fix this double free problem.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 433042a91f9373241307725b52de573933ffedbf - < b1813c220b76f60b1727984794377c4aa849d4c1affected 4f1fffa2376922f3d1d506e49c0fd445b023a28e - < c9f758ecf2562dfdd4adf12c22921b5de8366123affected 4f1fffa2376922f3d1d506e49c0fd445b023a28e - < 19ebc1e6cab334a8193398d4152deb76019b5d34affected 6.6.32 - < 6.6.59 |
Linux | Linux | affected 6.8unaffected 0 - < 6.8unaffected 6.6.59 - <= 6.6.*unaffected 6.11.6 - <= 6.11.*unaffected 6.12 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now