In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_scmi: Fix double free in OPTEE transport
Channels can be shared between protocols, avoid freeing the same channel descriptors twice when unloading the stack.
[
{
"deprecated": false,
"target": {
"file": "drivers/firmware/arm_scmi/optee.c",
"function": "scmi_optee_chan_free"
},
"digest": {
"function_hash": "37275005202118932214815648691565731041",
"length": 443.0
},
"id": "CVE-2024-49853-5b8e59b8",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6699567b0bbb378600a4dc0a1f929439a4e84a2c",
"signature_version": "v1"
},
{
"deprecated": false,
"target": {
"file": "drivers/firmware/arm_scmi/optee.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"44310154349152542889573587038100129520",
"107142463213297111175104238017922606661",
"312405828097523837829702578354140662085"
]
},
"id": "CVE-2024-49853-6acdce3f",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6699567b0bbb378600a4dc0a1f929439a4e84a2c",
"signature_version": "v1"
}
]