cbcvebase.
CVE-2024-38554
published 2024-06-19

CVE-2024-38554: In the Linux kernel, the following vulnerability has been resolved: ax25: Fix reference count leak issue of net_device There is a reference count leak issue of…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ax25: Fix reference count leak issue of net_device There is a reference count leak issue of the object "net_device" in ax25_dev_device_down(). When the ax25 device is shutting down, the ax25_dev_device_down() drops the reference count of net_device one or zero times depending on if we goto unlock_put or not, which will cause memory leak. In order to solve the above issue, decrease the reference count of net_device after dev->ax25_ptr is set to null.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.277 < 4.154.15
linuxlinux>= 4.19.240 < 4.204.20
linuxlinux>= 5.10.112 < 5.115.11
linuxlinux>= 5.15.35 < 5.165.16
linuxlinux>= 5.4.190 < 5.55.5
linuxlinux>= d01ffb9eee4af165d83b08dd73ebdf9fe94a519b < 3ec437f9bbae68e9b38115c4c91de995f73f6bad3ec437f9bbae68e9b38115c4c91de995f73f6bad
linuxlinux>= d01ffb9eee4af165d83b08dd73ebdf9fe94a519b < 965d940fb7414b310a22666503d2af69459c981b965d940fb7414b310a22666503d2af69459c981b
linuxlinux>= d01ffb9eee4af165d83b08dd73ebdf9fe94a519b < 8bad3a20a27be8d935f2aae08d3c6e743754944a8bad3a20a27be8d935f2aae08d3c6e743754944a
linuxlinux>= d01ffb9eee4af165d83b08dd73ebdf9fe94a519b < eef95df9b752699bddecefa851f64858247246e9eef95df9b752699bddecefa851f64858247246e9
linuxlinux>= d01ffb9eee4af165d83b08dd73ebdf9fe94a519b < 36e56b1b002bb26440403053f19f9e1a8bc075b236e56b1b002bb26440403053f19f9e1a8bc075b2
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.17 < 6.1.936.1.93
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12
linuxlinux_kernel>= 6.9 < 6.9.36.9.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.