Description
In the Linux kernel, the following vulnerability has been resolved: mm/slab: make __free(kfree) accept error pointers Currently, if an automatically freed allocation is an error pointer that will lead to a crash. An example of this is in wm831x_gpio_dbg_show(). 171 char *label __free(kfree) = gpiochip_dup_line_label(chip, i); 172 if (IS_ERR(label)) { 173 dev_err(wm831x->dev, "Failed to duplicate label\n"); 174 continue; 175 } The auto clean up function should check for error pointers as well, otherwise we're going to keep hitting issues like this.
Product status
f550466949e822afcd0b546a4fc35795930660bc (git) before 946771c2a2b1150f9b7286feadc3aa1e15a1eb16
3c6cc62ce1265aa5623e2e1b29c0fe258bf6e232 (git) before 9f6eb0ab4f95240589ee85fd9886a944cd3645b2
54da6a0924311c7cf5015533991e44fb8eb12773 (git) before ac6cf3ce9b7d12acb7b528248df5f87caa25fcdc
54da6a0924311c7cf5015533991e44fb8eb12773 (git) before 79cbe0be6c0317b215ddd8bd3e32f0afdac48543
54da6a0924311c7cf5015533991e44fb8eb12773 (git) before cd7eb8f83fcf258f71e293f7fc52a70be8ed0128
6.5
Any version before 6.5
6.1.91 (semver)
6.6.31 (semver)
6.8.10 (semver)
6.9 (original_commit_for_fix)
References
git.kernel.org/...c/946771c2a2b1150f9b7286feadc3aa1e15a1eb16
git.kernel.org/...c/9f6eb0ab4f95240589ee85fd9886a944cd3645b2
git.kernel.org/...c/ac6cf3ce9b7d12acb7b528248df5f87caa25fcdc
git.kernel.org/...c/79cbe0be6c0317b215ddd8bd3e32f0afdac48543
git.kernel.org/...c/cd7eb8f83fcf258f71e293f7fc52a70be8ed0128