← back
CVE-2026-31745

reset: gpio: fix double free in reset_add_gpio_aux_device() error path

EPSS 0.1%
In the Linux kernel, the following vulnerability has been resolved: reset: gpio: fix double free in reset_add_gpio_aux_device() error path When __auxiliary_device_add() fails, reset_add_gpio_aux_device() calls auxiliary_device_uninit(adev). The device release callback reset_gpio_aux_device_release() frees adev, but the current error path then calls kfree(adev) again, causing a double free. Keep kfree(adev) for the auxiliary_device_init() failure path, but avoid freeing adev after auxiliary_device_uninit().
Affected products
Linux · Linux

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →