In the Linux kernel, the following vulnerability has been resolved:
net: caif: fix memory leak in cfusbl_device_notify
In case of caif_enroll_dev() fail, allocated link_support won't be assigned to the corresponding structure. So simply free allocated pointer in case of error.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Mar 15, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 15, 2024 |
| Ubuntu | — | Upgrade linux-aws-hweUpgrade linuxUpgrade linux-bluefieldUpgrade linux-azure-fipsUpgrade linux-fipsUpgrade linux-oracle-5.4Upgrade linux-gcpUpgrade linux-gcp-5.4Upgrade linux-raspi-5.4Upgrade linux-awsUpgrade linux-aws-5.4Upgrade linux-gcp-4.15Upgrade linux-aws-fipsUpgrade linux-azureUpgrade linux-hweUpgrade linux-raspiUpgrade linux-hwe-5.4Upgrade linux-gkeopUpgrade linux-oracleUpgrade linux-azure-4.15Upgrade linux-gcp-fipsUpgrade linux-kvmUpgrade linux-azure-5.4 | Nov 19, 2024 | Mar 15, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub