Vulnerability Description
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.2, < 6.4 |
| Redhat | Enterprise Linux | 8.0 |
| Fedoraproject | Fedora | 39 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2023:6583
- https://access.redhat.com/errata/RHSA-2023:7077Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7370
- https://access.redhat.com/security/cve/CVE-2024-0443Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2257968Issue TrackingThird Party Advisory
- https://lore.kernel.org/linux-block/[email protected]/Mailing List
- https://access.redhat.com/errata/RHSA-2023:6583
- https://access.redhat.com/errata/RHSA-2023:7077Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7370
- https://access.redhat.com/security/cve/CVE-2024-0443Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2257968Issue TrackingThird Party Advisory
- https://lore.kernel.org/linux-block/[email protected]/Mailing List
FAQ
What is CVE-2024-0443?
CVE-2024-0443 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is on...
How severe is CVE-2024-0443?
CVE-2024-0443 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0443?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux, Fedoraproject Fedora.