CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's bnge driver, specifically during the release of auxiliary devices when the allocation of auxr_dev fails. This leads to a NULL pointer dereference, potentially causing system instability or crashes. Organizations using Linux systems with the bnge driver should prioritize this fix to ensure system reliability and prevent potential disruptions.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: bnge: Fix NULL pointer dereference in aux device release If allocation of auxr_dev fails during auxiliary device setup, the error path calls auxiliary_device_uninit(), which eventually invokes bnge_aux_dev_release(). The release callback unconditionally dereferences aux_priv->auxr_dev->pdev to retrieve the parent bnge_dev. Since auxr_dev has not yet been allocated on this failure path, the dereference results in a NULL pointer exception Retrieve the parent bnge_dev from the auxiliary device's parent instead of auxr_dev, and free auxr_dev only when it was successfully allocated. This allows the release callback to correctly clean up partially initialized auxiliary devices.