Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2024-38554
HistoryJun 19, 2024 - 1:35 p.m.

CVE-2024-38554 ax25: Fix reference count leak issue of net_device

2024-06-1913:35:25
Linux
github.com
2
ax25
reference count
net_device
memory leak
linux kernel

AI Score

6.7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

ax25: Fix reference count leak issue of net_device

There is a reference count leak issue of the object “net_device” in
ax25_dev_device_down(). When the ax25 device is shutting down, the
ax25_dev_device_down() drops the reference count of net_device one
or zero times depending on if we goto unlock_put or not, which will
cause memory leak.

In order to solve the above issue, decrease the reference count of
net_device after dev->ax25_ptr is set to null.

AI Score

6.7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial