cbcvebase.
CVE-2024-26655
published 2024-04-01

CVE-2024-26655: In the Linux kernel, the following vulnerability has been resolved: Fix memory leak in posix_clock_open() If the clk ops.open() function returns an error, we…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.3th percentile
In the Linux kernel, the following vulnerability has been resolved: Fix memory leak in posix_clock_open() If the clk ops.open() function returns an error, we don't release the pccontext we allocated for this clock. Re-organize the code slightly to make it all more obvious.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux>= 221e4d1e29bb442ac4c47bc8ee095abf009ee8f3 < ea2d9bfd422e92fd197f6a0b1fe7d81413b871e0ea2d9bfd422e92fd197f6a0b1fe7d81413b871e0
linuxlinux>= 60c6946675fc06dd2fd2b7a4b6fd1c1f046f1056 < a88649b49523e8cbe95254440d803e38c19d2341a88649b49523e8cbe95254440d803e38c19d2341
linuxlinux>= 60c6946675fc06dd2fd2b7a4b6fd1c1f046f1056 < 0200dd7ed2335469955d7e69cc1a6fa7df1f38470200dd7ed2335469955d7e69cc1a6fa7df1f3847
linuxlinux>= 60c6946675fc06dd2fd2b7a4b6fd1c1f046f1056 < 5b4cdd9c5676559b8a7c944ac5269b914b8c0bb85b4cdd9c5676559b8a7c944ac5269b914b8c0bb8
linuxlinux>= 63cb05f600940a3b4824509e7e0e909f040c82ee < f845cfa1a5ae697782bfcb843c9d06d3bc0cbbb6f845cfa1a5ae697782bfcb843c9d06d3bc0cbbb6
linuxlinux>= 72ba2204a2a71b6f25873f20eb9329e1e7a01d03 < 375abf52353ca5e1a2e5f763629a870f91d0c38a375abf52353ca5e1a2e5f763629a870f91d0c38a
linuxlinux>= a006fc4485159dc9bc3c4156f433f62b9c2b709c < 62a5adf57b56ee94075c889abea518b9dc66895d62a5adf57b56ee94075c889abea518b9dc66895d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.7 < 6.7.126.7.12
linuxlinux_kernel>= 6.8 < 6.8.36.8.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.