CVE-2024-41002

In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - Fix memory leak for sec resource release The AIV is one of the SEC resources. When releasing resources, it need to release the AIV resources at the same time. Otherwise, memory leakage occurs. The aiv resource release is added to the sec resource release function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Aug 2024, 16:18

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/36810d2db3496bb8b4db7ccda666674a5efc7b47 - () https://git.kernel.org/stable/c/36810d2db3496bb8b4db7ccda666674a5efc7b47 - Patch
References () https://git.kernel.org/stable/c/7c42ce556ff65995c8875c9ed64141c14238e7e6 - () https://git.kernel.org/stable/c/7c42ce556ff65995c8875c9ed64141c14238e7e6 - Patch
References () https://git.kernel.org/stable/c/9f21886370db451b0fdc651f6e41550a1da70601 - () https://git.kernel.org/stable/c/9f21886370db451b0fdc651f6e41550a1da70601 - Patch
References () https://git.kernel.org/stable/c/a886bcb0f67d1e3d6b2da25b3519de59098200c2 - () https://git.kernel.org/stable/c/a886bcb0f67d1e3d6b2da25b3519de59098200c2 - Patch
References () https://git.kernel.org/stable/c/bba4250757b4ae1680fea435a358d8093f254094 - () https://git.kernel.org/stable/c/bba4250757b4ae1680fea435a358d8093f254094 - Patch
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: crypto: hisilicon/sec: corrige la pérdida de memoria para la liberación de recursos de segundo El AIV es uno de los recursos de SEC. Al liberar recursos, es necesario liberar los recursos AIV al mismo tiempo. De lo contrario, se produce una pérdida de memoria. La liberación de recursos aiv se agrega a la función de liberación de recursos sec.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-401
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux

12 Jul 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-12 13:15

Updated : 2024-08-21 16:18


NVD link : CVE-2024-41002

Mitre link : CVE-2024-41002

CVE.ORG link : CVE-2024-41002


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime