Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
can: sja1000: fix use after free in ems_pcmcia_add_card()
If the last channel is not available then “dev” is freed. Fortunately, we can just use “pdev->irq” instead.
Also we should check if at least one channel was set up.
Details
- Affected product:
- Ubuntu 16.04 ELS
- Affected packages:
- linux-hwe @ 4.15.0 (+1 more)
In the Linux kernel, the following vulnerability has been resolved:
can: sja1000: fix use after free in ems_pcmcia_add_card()
If the last channel is not available then “dev” is freed. Fortunately, we can just use “pdev->irq” instead.
Also we should check if at least one channel was set up.