CVE Database
/

CVE-2024-50215

Back to search

CVE-2024-50215

Published: Nov 9, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup() for the same controller. So it's better to nullify it after release on error path in order to avoid double free later in nvmet_destroy_auth(). Found by Linux Verification Center (linuxtesting.org) with Svace.

VendorProductVersions

Linux

Linux

affected
7a277c37d3522e9b2777d762bbbcecafae2b1f8d - < c94e965f766321641ec38e4eece9ce8884543244
affected
7a277c37d3522e9b2777d762bbbcecafae2b1f8d - < c60af16e1d6cc2237d58336546d6adfc067b6b8f
affected
7a277c37d3522e9b2777d762bbbcecafae2b1f8d - < e61bd51e44409495d75847e9230736593e4c8710
affected
7a277c37d3522e9b2777d762bbbcecafae2b1f8d - < d2f551b1f72b4c508ab9298419f6feadc3b5d791

Linux

Linux

affected
6.0
unaffected
0 - < 6.0
unaffected
6.1.116 - <= 6.1.*
unaffected
6.6.60 - <= 6.6.*
unaffected
6.11.7 - <= 6.11.*

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now