Back

HIGH

crypto: iaa - Fix potential use after free bug

Published Oct 21, 2024

Description

The free_device_compression_mode(iaa_device, device_mode) function frees "device_mode" but it iss passed to iaa_compression_modes[i]->free() a few lines later resulting in a use after free.

The good news is that, so far as I can tell, nothing implements the ->free() function and the use after free happens in dead code. But, with this fix, when something does implement it, we'll be ready. :)

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Oct 21, 2024
Updated Aug 5, 2026
Reserved Sep 30, 2024

CISA Vulnrichment

Updated Oct 21, 2024

NVD

Status Modified
Modified Aug 4, 2026

Red Hat

Severity Moderate
Public date Oct 21, 2024
Bugzilla 2320195

ENISA EUVD

Assigner Linux
Published Oct 21, 2024
Updated Aug 5, 2026

GitHub

No data