CVE-2024-26860
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/04/2024
Last modified:
07/01/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
dm-integrity: fix a memory leak when rechecking the data<br />
<br />
Memory for the "checksums" pointer will leak if the data is rechecked<br />
after checksum failure (because the associated kfree won&#39;t happen due<br />
to &#39;goto skip_io&#39;).<br />
<br />
Fix this by freeing the checksums memory before recheck, and just use<br />
the "checksum_onstack" memory for storing checksum during recheck.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.80 (including) | 6.1.83 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.19 (including) | 6.6.23 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7.7 (including) | 6.7.11 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.8 (including) | 6.8.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/20e21c3c0195d915f33bc7321ee6b362177bf5bf
- https://git.kernel.org/stable/c/338580a7fb9b0930bb38098007e89cc0fc496bf7
- https://git.kernel.org/stable/c/55e565c42dce81a4e49c13262d5bc4eb4c2e588a
- https://git.kernel.org/stable/c/6d35654f03c35c273240d85ec67e3f2c3596c4e0
- https://git.kernel.org/stable/c/74abc2fe09691f3d836d8a54d599ca71f1e4287b
- https://git.kernel.org/stable/c/20e21c3c0195d915f33bc7321ee6b362177bf5bf
- https://git.kernel.org/stable/c/338580a7fb9b0930bb38098007e89cc0fc496bf7
- https://git.kernel.org/stable/c/55e565c42dce81a4e49c13262d5bc4eb4c2e588a
- https://git.kernel.org/stable/c/6d35654f03c35c273240d85ec67e3f2c3596c4e0
- https://git.kernel.org/stable/c/74abc2fe09691f3d836d8a54d599ca71f1e4287b



