Wind River Support Network

HomeDefectsLIN1023-14663
Acknowledged

LIN1023-14663 : Security Advisory - linux - CVE-2025-38699

Created: Sep 4, 2025    Updated: Sep 8, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:EOL][EOL]scsi: bfa: Double-free fix[EOL][EOL]When the bfad_im_probe() function fails during initialization, the memory[EOL]pointed to by bfad->im is freed without setting bfad->im to NULL.[EOL][EOL]Subsequently, during driver uninstallation, when the state machine enters[EOL]the bfad_sm_stopping state and calls the bfad_im_probe_undo() function,[EOL]it attempts to free the memory pointed to by bfad->im again, thereby[EOL]triggering a double-free vulnerability.[EOL][EOL]Set bfad->im to NULL if probing fails.

CREATE(Triage):(User=admin) [CVE-2025-38699 (https://nvd.nist.gov/vuln/detail/CVE-2025-38699)
Live chat
Online