Lucene search

K
osvGoogleOSV:CVE-2024-35926
HistoryMay 19, 2024 - 11:15 a.m.

CVE-2024-35926

2024-05-1911:15:00
Google
osv.dev
linux kernel
vulnerability
crypto
iaa
async_disable
descriptor
leak
testcases
software

AI Score

6.5

Confidence

Low

In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix async_disable descriptor leak The disable_async paths of iaa_compress/decompress() don’t free idxd descriptors in the async_disable case. Currently this only happens in the testcases where req->dst is set to null. Add a test to free them in those paths.