CVE-2024-35828

In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() In the for statement of lbs_allocate_cmd_buffer(), if the allocation of cmdarray[i].cmdbuf fails, both cmdarray and cmdarray[i].cmdbuf needs to be freed. Otherwise, there will be memleaks in lbs_allocate_cmd_buffer().
References
Link Resource
https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9 Patch
https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3a Patch
https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faab Patch
https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186 Patch
https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bf Patch
https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591 Patch
https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3 Patch
https://git.kernel.org/stable/c/e888c4461e109f7b93c3522afcbbaa5a8fdf29d2 Patch
https://git.kernel.org/stable/c/f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7 Patch
https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9 Patch
https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3a Patch
https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faab Patch
https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186 Patch
https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bf Patch
https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591 Patch
https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3 Patch
https://git.kernel.org/stable/c/e888c4461e109f7b93c3522afcbbaa5a8fdf29d2 Patch
https://git.kernel.org/stable/c/f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7 Patch
https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html Mailing List
https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html Mailing List
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

14 Jan 2025, 14:54

Type Values Removed Values Added
CWE CWE-401
References () https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9 - () https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9 - Patch
References () https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3a - () https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3a - Patch
References () https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faab - () https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faab - Patch
References () https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186 - () https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186 - Patch
References () https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bf - () https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bf - Patch
References () https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591 - () https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591 - Patch
References () https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3 - () https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3 - Patch
References () https://git.kernel.org/stable/c/e888c4461e109f7b93c3522afcbbaa5a8fdf29d2 - () https://git.kernel.org/stable/c/e888c4461e109f7b93c3522afcbbaa5a8fdf29d2 - Patch
References () https://git.kernel.org/stable/c/f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7 - () https://git.kernel.org/stable/c/f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7 - Patch
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - Mailing List
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html - Mailing List
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Debian debian Linux
Debian
Linux
Linux linux Kernel

21 Nov 2024, 09:20

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html -
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html -
References () https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9 - () https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9 -
References () https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3a - () https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3a -
References () https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faab - () https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faab -
References () https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186 - () https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186 -
References () https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bf - () https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bf -
References () https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591 - () https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591 -
References () https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3 - () https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3 -
References () https://git.kernel.org/stable/c/e888c4461e109f7b93c3522afcbbaa5a8fdf29d2 - () https://git.kernel.org/stable/c/e888c4461e109f7b93c3522afcbbaa5a8fdf29d2 -
References () https://git.kernel.org/stable/c/f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7 - () https://git.kernel.org/stable/c/f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7 -

05 Nov 2024, 10:16

Type Values Removed Values Added
References
  • {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}
  • {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}

27 Jun 2024, 13:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html -

25 Jun 2024, 22:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html -
Summary
  • (es) En el kernel de Linux se ha resuelto la siguiente vulnerabilidad: wifi: libertas: arreglados algunas memleaks en lbs_allocate_cmd_buffer() En la declaración for de lbs_allocate_cmd_buffer(), si falló la asignación de cmdarray[i].cmdbuf, tanto cmdarray como cmdarray[i] Es necesario liberar ].cmdbuf. De lo contrario, habrá fugas de memoria en lbs_allocate_cmd_buffer().

17 May 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-17 14:15

Updated : 2025-01-14 14:54


NVD link : CVE-2024-35828

Mitre link : CVE-2024-35828

CVE.ORG link : CVE-2024-35828


JSON object : View

Products Affected

linux

  • linux_kernel

debian

  • debian_linux
CWE
CWE-401

Missing Release of Memory after Effective Lifetime