CVE-2024-57980

Updated: 2026-02-27 03:35:10.40421

Description:

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix double free in error path If the uvc_status_init() function fails to allocate the int_urb, it will free the dev->status pointer but doesn't reset the pointer to NULL. This results in the kfree() call in uvc_status_cleanup() trying to double-free the memory. Fix it by resetting the dev->status pointer to NULL after freeing it. Reviewed by: Ricardo Ribalda <ribalda@chromium.org>


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2025:1747725447 2025-05-21 01:45:10
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Released CLSA-2025:1748366748 2025-06-10 00:31:13
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2025:1743676155 2025-04-17 03:57:20
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2025:1747688514 2025-05-21 01:45:08
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2025:1747688831 2025-05-21 01:45:08
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2025:1747688581 2025-05-21 01:45:07
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Needs Triage 2025-08-30 11:25:12
CloudLinux 7 ELS kernel 3.10.0 7.8 HIGH Ignored 2025-11-08 00:34:47 CloudLinux 6 and 7 support is limited and provided on demand. We strongly recommend upgrading to Clo...
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Released CLSA-2025:1748365686 2025-05-28 00:31:29
Oracle Linux 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2025:1743675538 2025-04-04 03:30:51
Total: 15