Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() In the for statement of lbs_allocate_cmd_buffer(), if the allocation of cmdarray[i].cmdbuf fails, both cmdarray and cmdarray[i].cmdbuf needs to be freed. Otherwise, there will be memleaks in lbs_allocate_cmd_buffer().
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.6.22, < 4.19.311 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9Patch
- https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3aPatch
- https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faabPatch
- https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186Patch
- https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bfPatch
- https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591Patch
- https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3Patch
- https://git.kernel.org/stable/c/e888c4461e109f7b93c3522afcbbaa5a8fdf29d2Patch
- https://git.kernel.org/stable/c/f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7Patch
- https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9Patch
- https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3aPatch
- https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faabPatch
- https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186Patch
- https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bfPatch
- https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591Patch
FAQ
What is CVE-2024-35828?
CVE-2024-35828 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() In the for statement of lbs_allocate_cmd_buffer(), if the allocatio...
How severe is CVE-2024-35828?
CVE-2024-35828 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-35828?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.