2024-05-10 13:13:09

by Siddh Raman Pant

[permalink] [raw]
Subject: Re: CVE-2024-26898: aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts

> In the Linux kernel, the following vulnerability has been resolved:
>
> aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts
>
> This patch is against CVE-2023-6270. The description of cve is:
>
> [...]
>
> The Linux kernel CVE team has assigned CVE-2024-26898 to this issue.

Isn't the new CVE a duplicate?

Thanks,
Siddh


Attachments:
signature.asc (849.00 B)
This is a digitally signed message part

2024-05-10 13:26:02

by Greg Kroah-Hartman

[permalink] [raw]
Subject: Re: CVE-2024-26898: aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts

On Fri, May 10, 2024 at 01:12:50PM +0000, Siddh Raman Pant wrote:
> > In the Linux kernel, the following vulnerability has been resolved:
> >
> > aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts
> >
> > This patch is against CVE-2023-6270. The description of cve is:
> >
> > [...]
> >
> > The Linux kernel CVE team has assigned CVE-2024-26898 to this issue.
>
> Isn't the new CVE a duplicate?

Given the lack of information in that older CVE, no, I do not think so
as there is no real information provided there at all.

thanks,

greg k-h