CVE-2024-53191
HIGHLinux Kernel 6.3-6.6.63, 6.7-6.11.10, 6.12-6.12.1 - Double Free in ath12k WiFi Driver
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix warning when unbinding If there is an error during some initialization related to firmware, the buffers dp->tx_ring[i].tx_status are released. However this is released again when the device is unbinded (ath12k_pci), and we get: WARNING: CPU: 0 PID: 2098 at mm/slub.c:4689 free_large_kmalloc+0x4d/0x80 Call Trace: free_large_kmalloc ath12k_dp_free ath12k_core_deinit ath12k_pci_remove ... The issue is always reproducible from a VM because the MSI addressing initialization is failing. In order to fix the issue, just set the buffers to NULL after releasing in order to avoid the double free.
References (4)
Core 4
Core References
Scores
CVSS v3
7.8
EPSS
0.0024
EPSS Percentile
14.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-415
Status
published
Products (14)
linux/Kernel
6.12.0 - 6.12.2linux
linux/Kernel
6.3.0 - 6.6.64linux
linux/Kernel
6.7.0 - 6.11.11linux
Linux/Linux
< 6.3
Linux/Linux
6.11.11 - 6.11.*
Linux/Linux
6.12.2 - 6.12.*
Linux/Linux
6.13
Linux/Linux
6.3
Linux/Linux
6.6.64 - 6.6.*
Linux/Linux
d889913205cf7ebda905b1e62c5867ed4e39f6c2 - 223b546c6222d42147eff034433002ca5e2e7e09
... and 4 more
Published
Dec 27, 2024
Tracked Since
Feb 18, 2026