In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix possible memory leak if device_add() fails If device_add() returns error, the name allocated by dev_set_name() needs be freed. As the comment of device_add() says, put_device() should be used to decrease the reference count in the error path. So fix this by calling put_device(), then the name can be freed in kobject_cleanp().
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | versions prior to 16.1R1 |
| Linux | Linux | < 6.2.9200.24614 |