CVE-2024-26734

HIGH

Linux Kernel 6.3-6.6.19, 6.7-6.7.7 - Use-After-Free in devlink_init()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: devlink: fix possible use-after-free and memory leaks in devlink_init() The pernet operations structure for the subsystem must be registered before registering the generic netlink family. Make an unregister in case of unsuccessful registration.

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 15.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401 CWE-416
Status published
Products (12)
linux/Kernel 6.3.0 - 6.6.19linux
linux/Kernel 6.7.0 - 6.7.7linux
Linux/Linux < 6.3
Linux/Linux 6.3
Linux/Linux 6.6.19 - 6.6.*
Linux/Linux 6.7.7 - 6.7.*
Linux/Linux 6.8
Linux/Linux 687125b5799cd5120437fa455cfccbe8537916ff - 919092bd5482b7070ae66d1daef73b600738f3a2
Linux/Linux 687125b5799cd5120437fa455cfccbe8537916ff - def689fc26b9a9622d2e2cb0c4933dd3b1c8071c
Linux/Linux 687125b5799cd5120437fa455cfccbe8537916ff - e91d3561e28d7665f4f837880501dc8755f635a9
... and 2 more
Published Apr 03, 2024
Tracked Since Feb 18, 2026