In the Linux kernel, the following vulnerability has been...
High severity
Unreviewed
Published
May 27, 2026
to the GitHub Advisory Database
•
Updated Jun 16, 2026
Description
Published by the National Vulnerability Database
May 27, 2026
Published to the GitHub Advisory Database
May 27, 2026
Last updated
Jun 16, 2026
In the Linux kernel, the following vulnerability has been resolved:
crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree
Annotating a local pointer variable, which will be assigned with the
kmalloc-family functions, with the
__cleanup(kfree)attribute willmake the address of the local variable, rather than the address returned
by kmalloc, passed to kfree directly and lead to a crash due to invalid
deallocation of stack address. According to other places in the repo,
the correct usage should be
__free(kfree). The code coincidentallycompiled because the parameter type
void *of kfree is compatible withthe desired type
struct { ... } **.References