Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ax25: Fix reference count leak issue of net_device There is a reference count leak issue of the object "net_device" in ax25_dev_device_down(). When the ax25 device is shutting down, the ax25_dev_device_down() drops the reference count of net_device one or zero times depending on if we goto unlock_put or not, which will cause memory leak. In order to solve the above issue, decrease the reference count of net_device after dev->ax25_ptr is set to null.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.17, < 6.1.93 |
References
- https://git.kernel.org/stable/c/36e56b1b002bb26440403053f19f9e1a8bc075b2Patch
- https://git.kernel.org/stable/c/3ec437f9bbae68e9b38115c4c91de995f73f6badPatch
- https://git.kernel.org/stable/c/8bad3a20a27be8d935f2aae08d3c6e743754944aPatch
- https://git.kernel.org/stable/c/965d940fb7414b310a22666503d2af69459c981bPatch
- https://git.kernel.org/stable/c/eef95df9b752699bddecefa851f64858247246e9Patch
- https://git.kernel.org/stable/c/36e56b1b002bb26440403053f19f9e1a8bc075b2Patch
- https://git.kernel.org/stable/c/3ec437f9bbae68e9b38115c4c91de995f73f6badPatch
- https://git.kernel.org/stable/c/8bad3a20a27be8d935f2aae08d3c6e743754944aPatch
- https://git.kernel.org/stable/c/965d940fb7414b310a22666503d2af69459c981bPatch
- https://git.kernel.org/stable/c/eef95df9b752699bddecefa851f64858247246e9Patch
FAQ
What is CVE-2024-38554?
CVE-2024-38554 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: ax25: Fix reference count leak issue of net_device There is a reference count leak issue of the object "net_device" in ax25_dev_de...
How severe is CVE-2024-38554?
CVE-2024-38554 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38554?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.