cbcvebase.
CVE-2024-38602
published 2024-06-19

CVE-2024-38602: In the Linux kernel, the following vulnerability has been resolved: ax25: Fix reference count leak issues of ax25_dev The ax25_addr_ax25dev() and…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved: ax25: Fix reference count leak issues of ax25_dev The ax25_addr_ax25dev() and ax25_dev_device_down() exist a reference count leak issue of the object "ax25_dev". Memory leak issue in ax25_addr_ax25dev(): The reference count of the object "ax25_dev" can be increased multiple times in ax25_addr_ax25dev(). This will cause a memory leak. Memory leak issues in ax25_dev_device_down(): The reference count of ax25_dev is set to 1 in ax25_dev_device_up() and then increase the reference count when ax25_dev is added to ax25_dev_list. As a result, the reference count of ax25_dev is 2. But when the device is shutting down. The ax25_dev_device_down() drops the reference count once or twice depending on if we goto unlock_put or not, which will cause memory leak. As for the issue of ax25_addr_ax25dev(), it is impossible for one pointer to be on a list twice. So add a break in ax25_addr_ax25dev(). As for the issue of ax25_dev_device_down(), increase the reference count of ax25_dev once in ax25_dev_device_up() and decrease the reference count of ax25_dev after it is removed from the ax25_dev_list.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.277 < 4.154.15
linuxlinux>= 4.19.240 < 4.204.20
linuxlinux>= 5.10.112 < 5.115.11
linuxlinux>= 5.15.35 < 5.165.16
linuxlinux>= 5.4.190 < 5.55.5
linuxlinux>= d01ffb9eee4af165d83b08dd73ebdf9fe94a519b < ae467750a3765dd1092eb29f58247950a2f9b60cae467750a3765dd1092eb29f58247950a2f9b60c
linuxlinux>= d01ffb9eee4af165d83b08dd73ebdf9fe94a519b < 38eb01edfdaa1562fa00429be2e33f45383b1b3a38eb01edfdaa1562fa00429be2e33f45383b1b3a
linuxlinux>= d01ffb9eee4af165d83b08dd73ebdf9fe94a519b < 81d8240b0a243b3ddd8fa8aa172f1acc2f7cc8f381d8240b0a243b3ddd8fa8aa172f1acc2f7cc8f3
linuxlinux>= d01ffb9eee4af165d83b08dd73ebdf9fe94a519b < 1ea02699c7557eeb35ccff2bd822de1b3e09d8681ea02699c7557eeb35ccff2bd822de1b3e09d868
linuxlinux>= d01ffb9eee4af165d83b08dd73ebdf9fe94a519b < b505e0319852b08a3a716b64620168eab21f4cedb505e0319852b08a3a716b64620168eab21f4ced
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.4.0-260.2944.4.0-260.294
linuxlinux_kernel>= 0 < 4.15.0-230.2424.15.0-230.242

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.