VYPR
High severity7.8NVD Advisory· Published Apr 3, 2024· Updated Jun 17, 2026

CVE-2024-26694

CVE-2024-26694

Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: fix double-free bug

The storage for the TLV PC register data wasn't done like all the other storage in the drv->fw area, which is cleared at the end of deallocation. Therefore, the freeing must also be done differently, explicitly NULL'ing it out after the free, since otherwise there's a nasty double-free bug here if a file fails to load after this has been parsed, and we get another free later (e.g. because no other file exists.) Fix that by adding the missing NULL assignment.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Linux/Kernel6 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.4,<6.6.18
    • cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 6.4
  • Linux/iwlwifillm-fuzzy
  • osv-coords
    Range: >= 6.4.0, < 6.6.18

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.