In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the out_scratch label without freeing the already allocated dsaddrs list, leading to a memory leak. Fix this by jumping to the out_err_drain_dsaddrs label, which properly frees the dsaddrs list before cleaning up other resources.
Update Linux/Linux to e2dde5dafb80f1af4028ed10ad255f42af71c784; Siemens/RUGGEDCOM RST2428P to V4.0; Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP to *; Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP to * if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanpnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() affects Linux/Linux (generic), Linux/Linux (generic), Siemens/RUGGEDCOM RST2428P (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic), Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (generic). Severity is unknown. In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the out_scratch label without freeing the already allocated dsaddrs list, leading to a memory leak. Fix this by jumping to the out_err_drain_dsaddrs label, which properly frees the dsaddrs list before cleaning up other resources.
AI coding agents often install or upgrade packages automatically in generic. A unknown vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range |
|---|
In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the out_scratch label without freeing the already allocated dsaddrs list, leading to a memory leak. Fix this by jumping to the out_err_drain_dsaddrs label, which properly frees the dsaddrs list before cleaning up other resources.
Update Linux/Linux to e2dde5dafb80f1af4028ed10ad255f42af71c784; Siemens/RUGGEDCOM RST2428P to V4.0; Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP to *; Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP to * if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanpnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() affects Linux/Linux (generic), Linux/Linux (generic), Siemens/RUGGEDCOM RST2428P (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic), Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (generic). Severity is unknown. In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the out_scratch label without freeing the already allocated dsaddrs list, leading to a memory leak. Fix this by jumping to the out_err_drain_dsaddrs label, which properly frees the dsaddrs list before cleaning up other resources.
AI coding agents often install or upgrade packages automatically in generic. A unknown vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range |
|---|
| Fixed version |
|---|
| Linux/Linuxgeneric | >=d67ae825a59d639e4d8b82413af84d854617a87e <e2dde5dafb80f1af4028ed10ad255f42af71c784 || >=d67ae825a59d639e4d8b82413af84d854617a87e <27c90d8ed81e7a289c9fe41b5e31d8bb609a3385 || >=d67ae825a59d639e4d8b82413af84d854617a87e <34b9dd179818ff7af2b36410985fd8166573c62d || >=d67ae825a59d639e4d8b82413af84d854617a87e <869862056e100973e76ce9f5f1b01837771b7722 || >=d67ae825a59d639e4d8b82413af84d854617a87e <86da7efd12295a7e2b4abde5e5984c821edd938f || >=d67ae825a59d639e4d8b82413af84d854617a87e <ed5d3f2f6885eb99f729e6ffd946e3aa058bd3eb || >=d67ae825a59d639e4d8b82413af84d854617a87e <0c728083654f0066f5e10a1d2b0bd0907af19a58 | e2dde5dafb80f1af4028ed10ad255f42af71c784, 27c90d8ed81e7a289c9fe41b5e31d8bb609a3385, 34b9dd179818ff7af2b36410985fd8166573c62d, 869862056e100973e76ce9f5f1b01837771b7722, 86da7efd12295a7e2b4abde5e5984c821edd938f, ed5d3f2f6885eb99f729e6ffd946e3aa058bd3eb, 0c728083654f0066f5e10a1d2b0bd0907af19a58 |
|---|---|---|
| Linux/Linuxgeneric | 4.0 | Not reported |
| Siemens/RUGGEDCOM RST2428Pgeneric | >=0 <V4.0 | V4.0 |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Fixed version |
|---|
| Linux/Linuxgeneric | >=d67ae825a59d639e4d8b82413af84d854617a87e <e2dde5dafb80f1af4028ed10ad255f42af71c784 || >=d67ae825a59d639e4d8b82413af84d854617a87e <27c90d8ed81e7a289c9fe41b5e31d8bb609a3385 || >=d67ae825a59d639e4d8b82413af84d854617a87e <34b9dd179818ff7af2b36410985fd8166573c62d || >=d67ae825a59d639e4d8b82413af84d854617a87e <869862056e100973e76ce9f5f1b01837771b7722 || >=d67ae825a59d639e4d8b82413af84d854617a87e <86da7efd12295a7e2b4abde5e5984c821edd938f || >=d67ae825a59d639e4d8b82413af84d854617a87e <ed5d3f2f6885eb99f729e6ffd946e3aa058bd3eb || >=d67ae825a59d639e4d8b82413af84d854617a87e <0c728083654f0066f5e10a1d2b0bd0907af19a58 | e2dde5dafb80f1af4028ed10ad255f42af71c784, 27c90d8ed81e7a289c9fe41b5e31d8bb609a3385, 34b9dd179818ff7af2b36410985fd8166573c62d, 869862056e100973e76ce9f5f1b01837771b7722, 86da7efd12295a7e2b4abde5e5984c821edd938f, ed5d3f2f6885eb99f729e6ffd946e3aa058bd3eb, 0c728083654f0066f5e10a1d2b0bd0907af19a58 |
|---|---|---|
| Linux/Linuxgeneric | 4.0 | Not reported |
| Siemens/RUGGEDCOM RST2428Pgeneric | >=0 <V4.0 | V4.0 |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard