CVE-2024-50215
Published: Nov 9, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup() for the same controller. So it's better to nullify it after release on error path in order to avoid double free later in nvmet_destroy_auth(). Found by Linux Verification Center (linuxtesting.org) with Svace.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 7a277c37d3522e9b2777d762bbbcecafae2b1f8d - < c94e965f766321641ec38e4eece9ce8884543244affected 7a277c37d3522e9b2777d762bbbcecafae2b1f8d - < c60af16e1d6cc2237d58336546d6adfc067b6b8faffected 7a277c37d3522e9b2777d762bbbcecafae2b1f8d - < e61bd51e44409495d75847e9230736593e4c8710affected 7a277c37d3522e9b2777d762bbbcecafae2b1f8d - < d2f551b1f72b4c508ab9298419f6feadc3b5d791 |
Linux | Linux | affected 6.0unaffected 0 - < 6.0unaffected 6.1.116 - <= 6.1.*unaffected 6.6.60 - <= 6.6.*unaffected 6.11.7 - <= 6.11.*+1 more versions |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now