CVE-2024-38539
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/06/2024
Last modified:
26/08/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
RDMA/cma: Fix kmemleak in rdma_core observed during blktests nvme/rdma use siw<br />
<br />
When running blktests nvme/rdma, the following kmemleak issue will appear.<br />
<br />
kmemleak: Kernel memory leak detector initialized (mempool available:36041)<br />
kmemleak: Automatic memory scanning thread started<br />
kmemleak: 2 new suspected memory leaks (see /sys/kernel/debug/kmemleak)<br />
kmemleak: 8 new suspected memory leaks (see /sys/kernel/debug/kmemleak)<br />
kmemleak: 17 new suspected memory leaks (see /sys/kernel/debug/kmemleak)<br />
kmemleak: 4 new suspected memory leaks (see /sys/kernel/debug/kmemleak)<br />
<br />
unreferenced object 0xffff88855da53400 (size 192):<br />
comm "rdma", pid 10630, jiffies 4296575922<br />
hex dump (first 32 bytes):<br />
37 00 00 00 00 00 00 00 c0 ff ff ff 1f 00 00 00 7...............<br />
10 34 a5 5d 85 88 ff ff 10 34 a5 5d 85 88 ff ff .4.].....4.]....<br />
backtrace (crc 47f66721):<br />
[] kmalloc_trace+0x30d/0x3b0<br />
[] alloc_gid_entry+0x47/0x380 [ib_core]<br />
[] add_modify_gid+0x166/0x930 [ib_core]<br />
[] ib_cache_update.part.0+0x6d8/0x910 [ib_core]<br />
[] ib_cache_setup_one+0x24a/0x350 [ib_core]<br />
[] ib_register_device+0x9e/0x3a0 [ib_core]<br />
[] 0xffffffffc2a3d389<br />
[] nldev_newlink+0x2b8/0x520 [ib_core]<br />
[] rdma_nl_rcv_msg+0x2c3/0x520 [ib_core]<br />
[]<br />
rdma_nl_rcv_skb.constprop.0.isra.0+0x23c/0x3a0 [ib_core]<br />
[] netlink_unicast+0x445/0x710<br />
[] netlink_sendmsg+0x761/0xc40<br />
[] __sys_sendto+0x3a9/0x420<br />
[] __x64_sys_sendto+0xdc/0x1b0<br />
[] do_syscall_64+0x93/0x180<br />
[] entry_SYSCALL_64_after_hwframe+0x71/0x79<br />
<br />
The root cause: rdma_put_gid_attr is not called when sgid_attr is set<br />
to ERR_PTR(-ENODEV).
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6 (including) | 6.6.33 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.8.12 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.9 (including) | 6.9.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



