CVE Vulnerabilities

CVE-2024-38157

Double Free

Published: Aug 13, 2024 | Modified: Aug 16, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Azure IoT SDK Remote Code Execution Vulnerability

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Azure_iot_hub_device_client_sdk Microsoft * 1.12.1 (excluding)

Potential Mitigations

References