CVE-2024-38554

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/06/2024
Last modified:
27/08/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ax25: Fix reference count leak issue of net_device<br /> <br /> There is a reference count leak issue of the object "net_device" in<br /> ax25_dev_device_down(). When the ax25 device is shutting down, the<br /> ax25_dev_device_down() drops the reference count of net_device one<br /> or zero times depending on if we goto unlock_put or not, which will<br /> cause memory leak.<br /> <br /> In order to solve the above issue, decrease the reference count of<br /> net_device after dev-&gt;ax25_ptr is set to null.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.17 (including) 6.1.93 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.8.12 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.9 (including) 6.9.3 (excluding)