CVE-2024-56710
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/12/2024
Last modified:
17/04/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ceph: fix memory leak in ceph_direct_read_write()<br />
<br />
The bvecs array which is allocated in iter_get_bvecs_alloc() is leaked<br />
and pages remain pinned if ceph_alloc_sparse_ext_map() fails.<br />
<br />
There is no need to delay the allocation of sparse_ext map until after<br />
the bvecs array is set up, so fix this by moving sparse_ext allocation<br />
a bit earlier. Also, make a similar adjustment in __ceph_sync_read()<br />
for consistency (a leak of the same kind in __ceph_sync_read() has been<br />
addressed differently).
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6 (including) | 6.6.69 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.7 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.13:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.13:rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



