cbcvebase.
CVE-2024-26894
published 2024-04-17

CVE-2024-26894: In the Linux kernel, the following vulnerability has been resolved: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit() After unregistering…

PriorityP424medium6CVSS 3.1
AVLACLPRHUINSUCHINAH
EPSS
0.25%
16.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit() After unregistering the CPU idle device, the memory associated with it is not freed, leading to a memory leak: unreferenced object 0xffff896282f6c000 (size 1024): comm "swapper/0", pid 1, jiffies 4294893170 hex dump (first 32 bytes): 00 00 00 00 0b 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace (crc 8836a742): [] kmalloc_trace+0x29d/0x340 [] acpi_processor_power_init+0xf3/0x1c0 [] __acpi_processor_start+0xd3/0xf0 [] acpi_processor_start+0x2c/0x50 [] really_probe+0xe2/0x480 [] __driver_probe_device+0x78/0x160 [] driver_probe_device+0x1f/0x90 [] __driver_attach+0xce/0x1c0 [] bus_for_each_dev+0x70/0xc0 [] bus_add_driver+0x112/0x210 [] driver_register+0x55/0x100 [] acpi_processor_driver_init+0x3b/0xc0 [] do_one_initcall+0x41/0x300 [] kernel_init_freeable+0x320/0x470 [] kernel_init+0x16/0x1b0 [] ret_from_fork+0x2d/0x50 Fix this by freeing the CPU idle device after unregistering it.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 3d339dcbb56d8d70c1b959aff87d74adc3a84eea < d351bcadab6caa6d8ce7159ff4b77e2da35c09fad351bcadab6caa6d8ce7159ff4b77e2da35c09fa
linuxlinux>= 3d339dcbb56d8d70c1b959aff87d74adc3a84eea < ea96bf3f80625cddba1391a87613356b1b45716dea96bf3f80625cddba1391a87613356b1b45716d
linuxlinux>= 3d339dcbb56d8d70c1b959aff87d74adc3a84eea < c2a30c81bf3cb9033fa9f5305baf7c377075e2e5c2a30c81bf3cb9033fa9f5305baf7c377075e2e5
linuxlinux>= 3d339dcbb56d8d70c1b959aff87d74adc3a84eea < 1cbaf4c793b0808532f4e7b40bc4be7cec2c78f21cbaf4c793b0808532f4e7b40bc4be7cec2c78f2
linuxlinux>= 3d339dcbb56d8d70c1b959aff87d74adc3a84eea < fad9bcd4d754cc689c19dc04d2c44b82c1a5d6c8fad9bcd4d754cc689c19dc04d2c44b82c1a5d6c8
linuxlinux>= 3d339dcbb56d8d70c1b959aff87d74adc3a84eea < 3d48e5be107429ff5d824e7f2a00d1b610d36fbc3d48e5be107429ff5d824e7f2a00d1b610d36fbc
linuxlinux>= 3d339dcbb56d8d70c1b959aff87d74adc3a84eea < 8d14a4d0afb49a5b8535d414c782bb334860e73e8d14a4d0afb49a5b8535d414c782bb334860e73e
linuxlinux>= 3d339dcbb56d8d70c1b959aff87d74adc3a84eea < cd5c2d0b09d5b6d3f0a7bbabe6761a4997e9dee9cd5c2d0b09d5b6d3f0a7bbabe6761a4997e9dee9
linuxlinux>= 3d339dcbb56d8d70c1b959aff87d74adc3a84eea < e18afcb7b2a12b635ac10081f943fcf84ddacc51e18afcb7b2a12b635ac10081f943fcf84ddacc51
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 3.7 < 4.19.3114.19.311
linuxlinux_kernel>= 4.20 < 5.4.2735.4.273
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.5 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.