CVE-2024-26860

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/04/2024
Last modified:
07/01/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> dm-integrity: fix a memory leak when rechecking the data<br /> <br /> Memory for the "checksums" pointer will leak if the data is rechecked<br /> after checksum failure (because the associated kfree won&amp;#39;t happen due<br /> to &amp;#39;goto skip_io&amp;#39;).<br /> <br /> Fix this by freeing the checksums memory before recheck, and just use<br /> the "checksum_onstack" memory for storing checksum during recheck.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.80 (including) 6.1.83 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6.19 (including) 6.6.23 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7.7 (including) 6.7.11 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.8 (including) 6.8.2 (excluding)