CVE-2024-35956Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
OSV6.8
EPSS
0.0%
top 99.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateJul 26

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix qgroup prealloc rsv leak in subvolume operations Create subvolume, create snapshot and delete subvolume all use btrfs_subvolume_reserve_metadata() to reserve metadata for the changes done to the parent subvolume's fs tree, which cannot be mediated in the normal way via start_transaction. When quota groups (squota or qgroups) are enabled, this reserves qgroup metadata of type PREALLOC. Once the operation is a

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

NVDlinux/linux_kernel5.9.56.1.120+3
Debianlinux/linux_kernel< 6.1.123-1+2
Ubuntulinux/linux_kernel< 6.8.0-38.38
CVEListV5linux/linuxe85fde5162bf1b242cbd6daf7dba0f9b457d592b945559be6e282a812dc48f7bcd5adc60901ea4a0+5
debiandebian/linux< linux 6.1.123-1 (bookworm)

Patches

🔴Vulnerability Details

6
OSV
linux-oracle vulnerabilities2024-07-26
OSV
linux-aws vulnerabilities2024-07-23
OSV
linux-gke, linux-nvidia vulnerabilities2024-07-16
OSV
linux, linux-azure, linux-gcp, linux-ibm, linux-intel, linux-lowlatency, linux-oem-6.8, linux-raspi vulnerabilities2024-07-11
GHSA
GHSA-3xrx-73h3-j99c: In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix qgroup prealloc rsv leak in subvolume operations Create subvo2024-05-20

📋Vendor Advisories

7
Ubuntu
Linux kernel vulnerabilities2024-07-26
Ubuntu
Linux kernel vulnerabilities2024-07-23
Ubuntu
Linux kernel vulnerabilities2024-07-16
Ubuntu
Linux kernel vulnerabilities2024-07-11
Red Hat
kernel: btrfs: qgroup: fix qgroup prealloc rsv leak in subvolume operations2024-05-20

💬Community

1
Bugzilla
CVE-2024-35956 kernel: btrfs: qgroup: fix qgroup prealloc rsv leak in subvolume operations2024-05-20