Back

HIGH

scsi: aacraid: Fix double-free on probe failure

Published Sep 13, 2024

Description

aac_probe_one() calls hardware-specific init functions through the aac_driver_ident::init pointer, all of which eventually call down to aac_init_adapter().

If aac_init_adapter() fails after allocating memory for aac_dev::queues, it frees the memory but does not clear that member.

After the hardware-specific init function returns an error, aac_probe_one() goes down an error path that frees the memory pointed to by aac_dev::queues, resulting.in a double-free.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 13, 2024
Updated Aug 5, 2026
Reserved Sep 11, 2024
CISA Vulnrichment
Updated Sep 29, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Sep 13, 2024