CVE-2024-0443
published 2024-01-12CVE-2024-0443: A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.1th percentile
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.3.11-1 (forky) | linux 6.3.11-1 (forky) |
| fedoraproject | fedora | — | — |
| chrome_chrome | — | — | |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.3.11-1 | 6.3.11-1 |
| linux | linux_kernel | >= 0 < 6.3.11-1 | 6.3.11-1 |
| linux | linux_kernel | >= 6.2 < 6.4 | 6.4 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2025-0443
vendor_chrome·2025-01-14·CVSS 8.8
CVE-2025-0443 [MEDIUM] Stable Channel Update for Desktop: CVE-2025-0443
Stable Channel Update for Desktop
CVE-2025-0443: Insufficient data validation in Extensions. Reported by Anonymous on 2024-10-31 [$1000][ 359949844 ] Low CVE-2025-0446: Inappropriate implementation in Extensions
Reported by Hafiizh on 2024-08-15 [$1000][ 375550814 ] Low CVE-2025-0447: Inappropriate implementation in Navigation
Severity: medium
Debian
CVE-2024-0443: linux - A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linu...
vendor_debian·2024·CVSS 5.5
CVE-2024-0443 [MEDIUM] CVE-2024-0443: linux - A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linu...
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.3.11-1)
sid: resolved (fixed in 6.3.11-1)
trixie: resolved (fixed in 6.3.11-1)
Red Hat
kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.
vendor_redhat·2023-12-14·CVSS 5.5
CVE-2024-0443 [MEDIUM] CWE-402 kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.
kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error.
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rsta
GHSA
GHSA-rqh4-x2v7-j34g: A flaw was found in the blkgs destruction path in block/blk-cgroup
ghsa_unreviewed·2024-01-12
CVE-2024-0443 [MEDIUM] CWE-402 GHSA-rqh4-x2v7-j34g: A flaw was found in the blkgs destruction path in block/blk-cgroup
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error.
OSV
CVE-2024-0443: A flaw was found in the blkgs destruction path in block/blk-cgroup
osv·2024-01-12·CVSS 5.5
CVE-2024-0443 [MEDIUM] CVE-2024-0443: A flaw was found in the blkgs destruction path in block/blk-cgroup
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2023:6583https://access.redhat.com/errata/RHSA-2023:7077https://access.redhat.com/errata/RHSA-2023:7370https://access.redhat.com/security/cve/CVE-2024-0443https://bugzilla.redhat.com/show_bug.cgi?id=2257968https://lore.kernel.org/linux-block/[email protected]/https://access.redhat.com/errata/RHSA-2023:6583https://access.redhat.com/errata/RHSA-2023:7077https://access.redhat.com/errata/RHSA-2023:7370https://access.redhat.com/security/cve/CVE-2024-0443https://bugzilla.redhat.com/show_bug.cgi?id=2257968https://lore.kernel.org/linux-block/[email protected]/
2024-01-12
Published