Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2x23-jxch-r563

Опубликовано: 17 сент. 2026
Источник: github
Github: Не прошло ревью

Описание

In the Linux kernel, the following vulnerability has been resolved:

rapidio: clear mport->net when rio_add_net() fails

rio_alloc_net() stores the newly allocated rio_net in mport->net before rio_scan_alloc_net() registers the device.

If rio_add_net() fails, rio_scan_alloc_net() drops the device reference with put_device(), which releases the rio_net through the device release callback. However, mport->net is left pointing at the freed object.

A later mport unregister path can then dereference the dangling mport->net pointer and may try to free the same rio_net again.

Clear mport->net in the rio_add_net() failure path, matching the cleanup done for the destID table allocation failure path.

In the Linux kernel, the following vulnerability has been resolved:

rapidio: clear mport->net when rio_add_net() fails

rio_alloc_net() stores the newly allocated rio_net in mport->net before rio_scan_alloc_net() registers the device.

If rio_add_net() fails, rio_scan_alloc_net() drops the device reference with put_device(), which releases the rio_net through the device release callback. However, mport->net is left pointing at the freed object.

A later mport unregister path can then dereference the dangling mport->net pointer and may try to free the same rio_net again.

Clear mport->net in the rio_add_net() failure path, matching the cleanup done for the destID table allocation failure path.

EPSS

Процентиль: 12%
0.0021
Низкий

Связанные уязвимости

ubuntu
4 дня назад

(In the Linux kernel, the following vulnerability has been resolved: r ...)

nvd
4 дня назад

In the Linux kernel, the following vulnerability has been resolved: rapidio: clear mport->net when rio_add_net() fails rio_alloc_net() stores the newly allocated rio_net in mport->net before rio_scan_alloc_net() registers the device. If rio_add_net() fails, rio_scan_alloc_net() drops the device reference with put_device(), which releases the rio_net through the device release callback. However, mport->net is left pointing at the freed object. A later mport unregister path can then dereference the dangling mport->net pointer and may try to free the same rio_net again. Clear mport->net in the rio_add_net() failure path, matching the cleanup done for the destID table allocation failure path.

msrc
2 дня назад

rapidio: clear mport->net when rio_add_net() fails

debian
4 дня назад

In the Linux kernel, the following vulnerability has been resolved: r ...

EPSS

Процентиль: 12%
0.0021
Низкий