In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a double free and a use after free.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | Versions earlier than 9.1.0.220(C635E1R1P2T8) |
| Linux | Linux | Versions earlier than 9.1.0.216(C569E1R1P1T8) |
| Linux | Linux | 10 Version 1607 for x64-based Systems |
| Linux | Linux | 10 Version 1709 for 32-bit Systems |