In the Linux kernel, the following vulnerability has been resolved:
coresight: syscfg: Fix memleak on registration failure in cscfg_create_device
device_register() calls device_initialize(), according to doc of device_initialize:
Use put_device() to give up your reference instead of freeing * @dev directly once you have called this function.
To prevent potential memleak, use put_device() for error handling.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-intel-iotgUpgrade linux-gcpUpgrade linux-kvmUpgrade linux-gkeUpgrade linux-realtimeUpgrade linux-raspiUpgrade linux-azure-5.15Upgrade linux-oracleUpgrade linux-intel-iotg-5.15Upgrade linux-lowlatencyUpgrade linux-ibmUpgrade linuxUpgrade linux-lowlatency-hwe-5.15Upgrade linux-hwe-5.15Upgrade linux-awsUpgrade linux-azure | Mar 19, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub