In the Linux kernel, the following vulnerability has been resolved:
pinctrl: nuvoton: fix a double free in ma35_pinctrl_dt_node_to_map_func()
'new_map' is allocated using devm_* which takes care of freeing the allocated data on device removal, call to
.dt_free_map = pinconf_generic_dt_free_map
double frees the map as pinconf_generic_dt_free_map() calls pinctrl_utils_free_map().
Fix this by using kcalloc() instead of auto-managed devm_kcalloc().
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-6.11.0-1015-oemUpgrade linux-image-lowlatency-64kUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-azureUpgrade linux-image-6.11.0-1009-awsUpgrade linux-image-6.11.0-1009-azureUpgrade linux-image-6.11.0-18-genericUpgrade linux-image-oracle-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.11.0-1010-lowlatencyUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-oem-24.04Upgrade linux-image-oem-24.04aUpgrade linux-image-lowlatencyUpgrade linux-image-raspiUpgrade linux-image-generic-64kUpgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-gcpUpgrade linux-image-genericUpgrade linux-image-azure-fdeUpgrade linux-image-realtimeUpgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-awsUpgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-oracleUpgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-oem-24.04bUpgrade linux-image-6.11.0-1009-gcpUpgrade linux-image-virtual | Feb 20, 2025 | Oct 29, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub