CVE-2024-26894 — Allocation of Resources Without Limits or Throttling in Linux
Severity
6.0MEDIUMNVD
OSV7.0OSV6.5OSV5.5
EPSS
0.0%
top 99.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 17
Latest updateJul 26
Description
In the Linux kernel, the following vulnerability has been resolved:
ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()
After unregistering the CPU idle device, the memory associated with
it is not freed, leading to a memory leak:
unreferenced object 0xffff896282f6c000 (size 1024):
comm "swapper/0", pid 1, jiffies 4294893170
hex dump (first 32 bytes):
00 00 00 00 0b 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 .............…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:HExploitability: 0.8 | Impact: 5.2
Affected Packages5 packages
▶CVEListV5linux/linux3d339dcbb56d8d70c1b959aff87d74adc3a84eea — d351bcadab6caa6d8ce7159ff4b77e2da35c09fa+9
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
22📋Vendor Advisories
22💬Community
1Bugzilla▶
CVE-2024-26894 kernel: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()↗2024-04-17