REDHAT-BUG-2334501: Use After Free
In the Linux kernel, the following vulnerability has been resolved:
net: ieee802154: do not leave a dangling sk pointer in ieee802154create()
sockinitdata() attaches the allocated sk object to the provided sock object. If ieee802154create() fails later, the allocated sk object is freed, but the dangling pointer remains in the provided sock object, which may allow use-after-free.
Clear the sk pointer in the sock object on error.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If ieee802154_create() fails after allocating the sk object, clear the sk pointer in the provided sock object on the error path to avoid leaving a dangling pointer.