cbcvebase.
CVE-2024-41025
published 2024-07-29

CVE-2024-41025: In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix memory leak in audio daemon attach operation Audio PD daemon send the…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.1th percentile
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix memory leak in audio daemon attach operation Audio PD daemon send the name as part of the init IOCTL call. This name needs to be copied to kernel for which memory is allocated. This memory is never freed which might result in memory leak. Free the memory when it is not needed.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.9.10-1 (forky)linux 6.9.10-1 (forky)
linuxlinux
linuxlinux>= 0871561055e666da421d779397efcc1e5e964cab < 8b8b82dcf393ceaca8c88939338fd4c30b5b11b28b8b82dcf393ceaca8c88939338fd4c30b5b11b2
linuxlinux>= 0871561055e666da421d779397efcc1e5e964cab < dbf4c31c9b039fd9734da156036492a2a7f78f64dbf4c31c9b039fd9734da156036492a2a7f78f64
linuxlinux>= 0871561055e666da421d779397efcc1e5e964cab < ad0bd973a033003ca578c42a760d1dc77aeea15ead0bd973a033003ca578c42a760d1dc77aeea15e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 6.2 < 6.6.416.6.41
linuxlinux_kernel>= 6.7 < 6.9.106.9.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.