CVE-2024-36954

In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __skb_linearize() doesn't free the skb when it fails, so move '*buf = NULL' after __skb_linearize(), so that the skb can be freed on the err path.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc6:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

14 Jan 2025, 16:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*
CWE CWE-401
First Time Debian debian Linux
Debian
Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/01cd1b7b685751ee422d00d050292a3d277652d6 - () https://git.kernel.org/stable/c/01cd1b7b685751ee422d00d050292a3d277652d6 - Patch
References () https://git.kernel.org/stable/c/2f87fd9476cf9725d774e6dcb7d17859c6a6d1ae - () https://git.kernel.org/stable/c/2f87fd9476cf9725d774e6dcb7d17859c6a6d1ae - Patch
References () https://git.kernel.org/stable/c/3210d34fda4caff212cb53729e6bd46de604d565 - () https://git.kernel.org/stable/c/3210d34fda4caff212cb53729e6bd46de604d565 - Patch
References () https://git.kernel.org/stable/c/42c8471b0566c7539e7dd584b4d0ebd3cec8cb2c - () https://git.kernel.org/stable/c/42c8471b0566c7539e7dd584b4d0ebd3cec8cb2c - Patch
References () https://git.kernel.org/stable/c/614c5a5ae45a921595952117b2e2bd4d4bf9b574 - () https://git.kernel.org/stable/c/614c5a5ae45a921595952117b2e2bd4d4bf9b574 - Patch
References () https://git.kernel.org/stable/c/97bf6f81b29a8efaf5d0983251a7450e5794370d - () https://git.kernel.org/stable/c/97bf6f81b29a8efaf5d0983251a7450e5794370d - Patch
References () https://git.kernel.org/stable/c/adbce6d20da6254c86425a8d4359b221b5ccbccd - () https://git.kernel.org/stable/c/adbce6d20da6254c86425a8d4359b221b5ccbccd - Patch
References () https://git.kernel.org/stable/c/d03a82f4f8144befdc10518e732e2a60b34c870e - () https://git.kernel.org/stable/c/d03a82f4f8144befdc10518e732e2a60b34c870e - Patch
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html - Mailing List
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html - Mailing List

21 Nov 2024, 09:22

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html -
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html -
References () https://git.kernel.org/stable/c/01cd1b7b685751ee422d00d050292a3d277652d6 - () https://git.kernel.org/stable/c/01cd1b7b685751ee422d00d050292a3d277652d6 -
References () https://git.kernel.org/stable/c/2f87fd9476cf9725d774e6dcb7d17859c6a6d1ae - () https://git.kernel.org/stable/c/2f87fd9476cf9725d774e6dcb7d17859c6a6d1ae -
References () https://git.kernel.org/stable/c/3210d34fda4caff212cb53729e6bd46de604d565 - () https://git.kernel.org/stable/c/3210d34fda4caff212cb53729e6bd46de604d565 -
References () https://git.kernel.org/stable/c/42c8471b0566c7539e7dd584b4d0ebd3cec8cb2c - () https://git.kernel.org/stable/c/42c8471b0566c7539e7dd584b4d0ebd3cec8cb2c -
References () https://git.kernel.org/stable/c/614c5a5ae45a921595952117b2e2bd4d4bf9b574 - () https://git.kernel.org/stable/c/614c5a5ae45a921595952117b2e2bd4d4bf9b574 -
References () https://git.kernel.org/stable/c/97bf6f81b29a8efaf5d0983251a7450e5794370d - () https://git.kernel.org/stable/c/97bf6f81b29a8efaf5d0983251a7450e5794370d -
References () https://git.kernel.org/stable/c/adbce6d20da6254c86425a8d4359b221b5ccbccd - () https://git.kernel.org/stable/c/adbce6d20da6254c86425a8d4359b221b5ccbccd -
References () https://git.kernel.org/stable/c/d03a82f4f8144befdc10518e732e2a60b34c870e - () https://git.kernel.org/stable/c/d03a82f4f8144befdc10518e732e2a60b34c870e -

05 Nov 2024, 10:17

Type Values Removed Values Added
References
  • {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}
  • {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}

27 Jun 2024, 14:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00019.html -

27 Jun 2024, 12:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: tipc: soluciona un posible memleak en tipc_buf_append __skb_linearize() no libera el skb cuando falla, así que mueve '*buf = NULL' después de __skb_linearize(), para que el skb se puede liberar en la ruta de error.

30 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-30 16:15

Updated : 2025-01-14 16:27


NVD link : CVE-2024-36954

Mitre link : CVE-2024-36954

CVE.ORG link : CVE-2024-36954


JSON object : View

Products Affected

linux

  • linux_kernel

debian

  • debian_linux
CWE
CWE-401

Missing Release of Memory after Effective Lifetime