CVE-2024-26860

In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix a memory leak when rechecking the data Memory for the "checksums" pointer will leak if the data is rechecked after checksum failure (because the associated kfree won't happen due to 'goto skip_io'). Fix this by freeing the checksums memory before recheck, and just use the "checksum_onstack" memory for storing checksum during recheck.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

07 Jan 2025, 17:13

Type Values Removed Values Added
CWE CWE-401
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/20e21c3c0195d915f33bc7321ee6b362177bf5bf - () https://git.kernel.org/stable/c/20e21c3c0195d915f33bc7321ee6b362177bf5bf - Patch
References () https://git.kernel.org/stable/c/338580a7fb9b0930bb38098007e89cc0fc496bf7 - () https://git.kernel.org/stable/c/338580a7fb9b0930bb38098007e89cc0fc496bf7 - Patch
References () https://git.kernel.org/stable/c/55e565c42dce81a4e49c13262d5bc4eb4c2e588a - () https://git.kernel.org/stable/c/55e565c42dce81a4e49c13262d5bc4eb4c2e588a - Patch
References () https://git.kernel.org/stable/c/6d35654f03c35c273240d85ec67e3f2c3596c4e0 - () https://git.kernel.org/stable/c/6d35654f03c35c273240d85ec67e3f2c3596c4e0 - Patch
References () https://git.kernel.org/stable/c/74abc2fe09691f3d836d8a54d599ca71f1e4287b - () https://git.kernel.org/stable/c/74abc2fe09691f3d836d8a54d599ca71f1e4287b - Patch

21 Nov 2024, 09:03

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/20e21c3c0195d915f33bc7321ee6b362177bf5bf - () https://git.kernel.org/stable/c/20e21c3c0195d915f33bc7321ee6b362177bf5bf -
References () https://git.kernel.org/stable/c/338580a7fb9b0930bb38098007e89cc0fc496bf7 - () https://git.kernel.org/stable/c/338580a7fb9b0930bb38098007e89cc0fc496bf7 -
References () https://git.kernel.org/stable/c/55e565c42dce81a4e49c13262d5bc4eb4c2e588a - () https://git.kernel.org/stable/c/55e565c42dce81a4e49c13262d5bc4eb4c2e588a -
References () https://git.kernel.org/stable/c/6d35654f03c35c273240d85ec67e3f2c3596c4e0 - () https://git.kernel.org/stable/c/6d35654f03c35c273240d85ec67e3f2c3596c4e0 -
References () https://git.kernel.org/stable/c/74abc2fe09691f3d836d8a54d599ca71f1e4287b - () https://git.kernel.org/stable/c/74abc2fe09691f3d836d8a54d599ca71f1e4287b -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: dm-integrity: soluciona una pérdida de memoria al volver a verificar los datos. La memoria para el puntero de "sumas de verificación" se perderá si los datos se vuelven a verificar después de una falla en la suma de verificación (porque el kfree asociado no sucederá). debido a 'goto skip_io'). Solucione este problema liberando la memoria de sumas de verificación antes de volver a verificar y simplemente use la memoria "checksum_onstack" para almacenar la suma de verificación durante la nueva verificación.

17 Apr 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-17 11:15

Updated : 2025-01-07 17:13


NVD link : CVE-2024-26860

Mitre link : CVE-2024-26860

CVE.ORG link : CVE-2024-26860


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime