In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf' In fastrpc_req_mmap() error path, the fastrpc buffer is freed in fastrpc_req_munmap_impl() if unmap is successful. But in the end, there is an unconditional call to fastrpc_buf_free(). So the above case triggers the double free of fastrpc buf.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 12.3(14)YM3 |
| Linux | Linux | 12.3(14)YM7 |
| Linux | Linux | 3.5 on Windows 10 Version 1703 for x64-based Systems |
| Linux | Linux | 3.5 on Windows Server 2012 R2 |