-

CVE-2025-38699

In the Linux kernel, the following vulnerability has been resolved:

scsi: bfa: Double-free fix

When the bfad_im_probe() function fails during initialization, the memory
pointed to by bfad->im is freed without setting bfad->im to NULL.

Subsequently, during driver uninstallation, when the state machine enters
the bfad_sm_stopping state and calls the bfad_im_probe_undo() function,
it attempts to free the memory pointed to by bfad->im again, thereby
triggering a double-free vulnerability.

Set bfad->im to NULL if probing fails.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 684c92bb08a25ed3c0356bc7eb532ed5b19588dd
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 9337c2affbaebe00b75fdf84ea0e2fcf93c140af
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < ba024d92564580bb90ec367248ace8efe16ce815
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 8e03dd9fadf76db5b9799583074a1a2a54f787f1
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 39cfe2c83146aad956318f866d0ee471b7a61fa5
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 13f613228cf3c96a038424cd97aa4d6aadc66294
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 8456f862cb95bcc3a831e1ba87c0c17068be0f3f
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 50d9bd48321038bd6e15af5a454bbcd180cf6f80
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < add4c4850363d7c1b72e8fce9ccb21fdd2cf5dc9
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version <= 5.4.*
Version 5.4.297
Status unaffected
Version <= 5.10.*
Version 5.10.241
Status unaffected
Version <= 5.15.*
Version 5.15.190
Status unaffected
Version <= 6.1.*
Version 6.1.149
Status unaffected
Version <= 6.6.*
Version 6.6.103
Status unaffected
Version <= 6.12.*
Version 6.12.43
Status unaffected
Version <= 6.15.*
Version 6.15.11
Status unaffected
Version <= 6.16.*
Version 6.16.2
Status unaffected
Version <= *
Version 6.17-rc1
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.143
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string