CVE-2024-35972

medium

Description

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix possible memory leak in bnxt_rdma_aux_device_init() If ulp = kzalloc() fails, the allocated edev will leak because it is not properly assigned and the cleanup path will not be able to free it. Fix it by assigning it properly immediately after allocation.

References

https://git.kernel.org/stable/c/c60ed825530b8c0cc2b524efd39b1d696ec54004

https://git.kernel.org/stable/c/c60ed825530b8c0cc2b524efd39b1d696ec54004

https://git.kernel.org/stable/c/7ac10c7d728d75bc9daaa8fade3c7a3273b9a9ff

https://git.kernel.org/stable/c/7ac10c7d728d75bc9daaa8fade3c7a3273b9a9ff

https://git.kernel.org/stable/c/10a9d6a7513f93d7faffcb341af0aa42be8218fe

https://git.kernel.org/stable/c/10a9d6a7513f93d7faffcb341af0aa42be8218fe

Details

Source: Mitre, NVD

Published: 2024-05-20

Updated: 2024-05-23

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium