
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-36973 is a vulnerability discovered in the Linux kernel affecting the Microchip PCI1xxxx driver. The issue was identified and disclosed on June 17, 2024, specifically impacting the error handling path in the gp_aux_bus_probe() function. The vulnerability affects Linux kernel versions from 6.1 up to (excluding) 6.1.95, 6.2 up to (excluding) 6.6.35, 6.7 up to (excluding) 6.9.6, and 6.10 release candidates (NVD).
The vulnerability is classified as a double free condition (CWE-415) in the Linux kernel's Microchip PCI1xxxx driver. The issue occurs when auxiliary_device_add() returns an error and calls auxiliary_device_uninit(), where the callback function gp_auxiliary_device_release() calls ida_free() and kfree(aux_device_wrapper) to free memory. The bug results in attempting to free the same memory again in the error handling path (Kernel Patch). The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).
The double free vulnerability could potentially lead to memory corruption, which may result in privilege escalation, denial of service, or information disclosure on affected systems. The high CVSS score indicates significant potential impact on the confidentiality, integrity, and availability of the system (NVD).
The vulnerability requires local access with low privileges to exploit. No active exploits have been reported in the wild at the time of assessment (NVD).
The vulnerability has been fixed by modifying the error handling path to skip redundant cleanup functions. The fix has been implemented in various Linux kernel versions, including 6.8.0-44.44 for Ubuntu 24.04 LTS and 6.1.119-1~deb11u1 for Debian 11. Users are advised to update their systems to the patched versions (Ubuntu, Debian).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."