cbcvebase.
CVE-2024-41001
published 2024-07-12

CVE-2024-41001: In the Linux kernel, the following vulnerability has been resolved: io_uring/sqpoll: work around a potential audit memory leak kmemleak complains that there's…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.0th percentile
In the Linux kernel, the following vulnerability has been resolved: io_uring/sqpoll: work around a potential audit memory leak kmemleak complains that there's a memory leak related to connect handling: unreferenced object 0xffff0001093bdf00 (size 128): comm "iou-sqp-455", pid 457, jiffies 4294894164 hex dump (first 32 bytes): 02 00 fa ea 7f 00 00 01 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace (crc 2e481b1a): [] kmemleak_alloc+0x30/0x38 [] kmalloc_trace+0x228/0x358 [] __audit_sockaddr+0xd0/0x138 [] move_addr_to_kernel+0x1a0/0x1f8 [] io_connect_prep+0x1ec/0x2d4 [] io_submit_sqes+0x588/0x1e48 [] io_sq_thread+0x8a4/0x10e4 [] ret_from_fork+0x10/0x20 which can can happen if: 1) The command type does something on the prep side that triggers an audit call. 2) The thread hasn't done any operations before this that triggered an audit call inside ->issue(), where we have audit_uring_entry() and audit_uring_exit(). Work around this by issuing a blanket NOP operation before the SQPOLL does anything.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 2b188cc1bb857a9d4701ae59aa7768b5124e262e < 55c22375cbaa24f77dd13f9ae0642915444a122755c22375cbaa24f77dd13f9ae0642915444a1227
linuxlinux>= 2b188cc1bb857a9d4701ae59aa7768b5124e262e < 9e810bd995823786ea30543e480e8a573e5e56679e810bd995823786ea30543e480e8a573e5e5667
linuxlinux>= 2b188cc1bb857a9d4701ae59aa7768b5124e262e < a40e90d9304629002fb17200f7779823a81191d3a40e90d9304629002fb17200f7779823a81191d3
linuxlinux>= 2b188cc1bb857a9d4701ae59aa7768b5124e262e < c4ce0ab27646f4206a9eb502d6fe45cb080e1caec4ce0ab27646f4206a9eb502d6fe45cb080e1cae
linuxlinux_kernel< 6.1.966.1.96
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.2 < 6.6.366.6.36
linuxlinux_kernel>= 6.7 < 6.9.76.9.7
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.