In the Linux kernel, the following vulnerability has been resolved:
usb: misc: ljca: Fix double free in error handling path
When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function ljca_auxdev_release calls kfree(auxdev->dev.platform_data) to free the parameter data of the function ljca_new_client_device. The callers of ljca_new_client_device shouldn't call kfree() again in the error handling path to free the platform data.
Fix this by cleaning up the redundant kfree() in all callers and adding kfree() the passed in platform_data on errors which happen before auxiliary_device_init() succeeds .
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-oem-24.04aUpgrade linux-image-gcpUpgrade linux-image-oracle-64kUpgrade linux-image-6.8.0-1004-gkeUpgrade linux-image-virtualUpgrade linux-image-6.8.0-1009-awsUpgrade linux-image-6.8.0-35-lowlatencyUpgrade linux-image-awsUpgrade linux-image-6.8.0-1008-gcpUpgrade linux-image-6.8.0-1008-azure-fdeUpgrade linux-image-6.8.0-35-genericUpgrade linux-image-oracleUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oem-24.04Upgrade linux-image-6.8.0-1006-oemUpgrade linux-image-gkeUpgrade linux-image-6.8.0-35-lowlatency-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.8.0-1006-oracle-64kUpgrade linux-image-ibm-classicUpgrade linux-image-6.8.0-35-generic-64kUpgrade linux-image-6.8.0-1008-azureUpgrade linux-image-generic-64kUpgrade linux-image-lowlatency-64kUpgrade linux-image-kvmUpgrade linux-image-ibmUpgrade linux-image-lowlatencyUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-raspiUpgrade linux-image-generic-lpaeUpgrade linux-image-genericUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-azure-fdeUpgrade linux-image-6.8.0-1006-ibmUpgrade linux-image-6.8.0-1005-raspiUpgrade linux-image-azureUpgrade linux-image-6.8.0-1006-oracle | Jul 1, 2024 | Apr 1, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub