CVE-2024-36973
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-36973 is a vulnerability discovered in the Linux kernel affecting the Microchip PCI1xxxx driver. The issue was identified and disclosed on June 17, 2024, specifically impacting the error handling path in the gp_aux_bus_probe() function. The vulnerability affects Linux kernel versions from 6.1 up to (excluding) 6.1.95, 6.2 up to (excluding) 6.6.35, 6.7 up to (excluding) 6.9.6, and 6.10 release candidates (NVD).

Technical details

The vulnerability is classified as a double free condition (CWE-415) in the Linux kernel's Microchip PCI1xxxx driver. The issue occurs when auxiliary_device_add() returns an error and calls auxiliary_device_uninit(), where the callback function gp_auxiliary_device_release() calls ida_free() and kfree(aux_device_wrapper) to free memory. The bug results in attempting to free the same memory again in the error handling path (Kernel Patch). The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The double free vulnerability could potentially lead to memory corruption, which may result in privilege escalation, denial of service, or information disclosure on affected systems. The high CVSS score indicates significant potential impact on the confidentiality, integrity, and availability of the system (NVD).

Exploitability

The vulnerability requires local access with low privileges to exploit. No active exploits have been reported in the wild at the time of assessment (NVD).

Mitigation and workarounds

The vulnerability has been fixed by modifying the error handling path to skip redundant cleanup functions. The fix has been implemented in various Linux kernel versions, including 6.8.0-44.44 for Ubuntu 24.04 LTS and 6.1.119-1~deb11u1 for Debian 11. Users are advised to update their systems to the patched versions (Ubuntu, Debian).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64597CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux-aws-5.4
NoYesAug 06, 2026
CVE-2026-68480HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel-modules-partner
NoYesAug 06, 2026
CVE-2026-64598HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.8
NoYesAug 06, 2026
CVE-2026-64604HIGH7.7
  • Linux Kernel logoLinux Kernel
  • linux-riscv-5.15
NoYesAug 06, 2026
CVE-2026-64603NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg-5.15
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management