In the Linux kernel, the following vulnerability has been resolved:
power: supply: rk817: Fix node refcount leak
Dan Carpenter reports that the Smatch static checker warning has found that there is another refcount leak in the probe function. While of_node_put() was added in one of the return paths, it should in fact be added for ALL return paths that return an error and at driver removal time.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Mar 2, 2024 |
| Ubuntu | — | Upgrade linux-gcp-6.5Upgrade linux-laptopUpgrade linux-lowlatency-hwe-6.5Upgrade linux-nvidia-6.5Upgrade linux-awsUpgrade linuxUpgrade linux-hwe-6.5Upgrade linux-starfiveUpgrade linux-riscvUpgrade linux-raspiUpgrade linux-oracle-6.5Upgrade linux-gcpUpgrade linux-oracleUpgrade linux-oem-6.5Upgrade linux-lowlatency | Nov 19, 2024 | Mar 2, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub