In the Linux kernel, the following vulnerability has been resolved: ath10k: Fix a use after free in ath10k_htc_send_bundle In ath10k_htc_send_bundle, the bundle_skb could be freed by dev_kfree_skb_any(bundle_skb). But the bundle_skb is used later by bundle_skb->len. As skb_len = bundle_skb->len, my patch replaces bundle_skb->len to skb_len after the bundle_skb was freed.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 10.1.3 |
| Linux | Linux | n/a |
| Linux | Linux | n/a |
| Linux | Linux | n/a |