cbcvebase.
CVE-2024-39489
published 2024-07-10

CVE-2024-39489: In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix memleak in seg6_hmac_init_algo seg6_hmac_init_algo returns without cleaning…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix memleak in seg6_hmac_init_algo seg6_hmac_init_algo returns without cleaning up the previous allocations if one fails, so it's going to leak all that memory and the crypto tfms. Update seg6_hmac_exit to only free the memory when allocated, so we can reuse the code directly.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= bf355b8d2c30a289232042cacc1cfaea4923936c < afd5730969aec960a2fee4e5ee839a6014643976afd5730969aec960a2fee4e5ee839a6014643976
linuxlinux>= bf355b8d2c30a289232042cacc1cfaea4923936c < 4a3fcf53725b70010d1cf869a2ba549fed6b8fb34a3fcf53725b70010d1cf869a2ba549fed6b8fb3
linuxlinux>= bf355b8d2c30a289232042cacc1cfaea4923936c < daf341e0a2318b813427d5a78788c86f4a7f02bedaf341e0a2318b813427d5a78788c86f4a7f02be
linuxlinux>= bf355b8d2c30a289232042cacc1cfaea4923936c < 61d31ac85b4572d11f8071855c0ccb4f32d76c0c61d31ac85b4572d11f8071855c0ccb4f32d76c0c
linuxlinux>= bf355b8d2c30a289232042cacc1cfaea4923936c < 599a5654215092ac22bfc453f4fd3959c55ea821599a5654215092ac22bfc453f4fd3959c55ea821
linuxlinux>= bf355b8d2c30a289232042cacc1cfaea4923936c < 0e44d6cbe8de983470c3d2f978649783384fdcb60e44d6cbe8de983470c3d2f978649783384fdcb6
linuxlinux>= bf355b8d2c30a289232042cacc1cfaea4923936c < f6a99ef4e056c20a138a95cc51332b2b96c8f383f6a99ef4e056c20a138a95cc51332b2b96c8f383
linuxlinux>= bf355b8d2c30a289232042cacc1cfaea4923936c < efb9f4f19f8e37fde43dfecebc80292d179f56c6efb9f4f19f8e37fde43dfecebc80292d179f56c6
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 4.10 < 4.19.3164.19.316
linuxlinux_kernel>= 4.20 < 5.4.2785.4.278
linuxlinux_kernel>= 5.11 < 5.15.1615.15.161
linuxlinux_kernel>= 5.16 < 6.1.936.1.93
linuxlinux_kernel>= 5.5 < 5.10.2195.10.219
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.9.46.9.4
msrcazl3_kernel_6.6.22.1-2_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.