In the Linux kernel, the following vulnerability has been resolved:
efi/libstub: Free correct pointer on failure
cmdline_ptr is an out parameter, which is not allocated by the function
itself, and likely points into the caller's stack.
cmdline refers to the pool allocation that should be freed when cleaning
up after a failure, so pass this instead to free_pool().
Metrics
Affected Vendors & Products
References
History
Fri, 27 Dec 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the Linux kernel, the following vulnerability has been resolved: efi/libstub: Free correct pointer on failure cmdline_ptr is an out parameter, which is not allocated by the function itself, and likely points into the caller's stack. cmdline refers to the pool allocation that should be freed when cleaning up after a failure, so pass this instead to free_pool(). | |
Title | efi/libstub: Free correct pointer on failure | |
References |
|
MITRE
Status: PUBLISHED
Assigner: Linux
Published: 2024-12-27T14:23:16.231Z
Updated: 2024-12-27T14:23:16.231Z
Reserved: 2024-12-27T14:03:05.998Z
Link: CVE-2024-56573
Vulnrichment
No data.
NVD
Status : Received
Published: 2024-12-27T15:15:16.320
Modified: 2024-12-27T15:15:16.320
Link: CVE-2024-56573
Redhat
No data.