CVE-2024-26694

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 3, 2024
Updated: Jan 7, 2025
CWE ID 415

Summary

CVE-2024-26694 is a vulnerability affecting the Linux kernel's iwlwifi driver. A double-free bug was identified, where the storage for TLV PC register data was not properly cleared upon deallocation. As a result, if a file fails to load after parsing this data, a second free operation may occur, leading to a double-free condition. To address this issue, the missing NULL assignment has been added to explicitly clear the memory before freeing it.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share