CVE-2024-26833
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix memory leak in dm_sw_fini() After destroying dmub_srv, the memory associated with it is not freed, causing a memory leak: unreferenced object 0xffff896302b45800…
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix memory leak in dm_sw_fini() After destroying dmub_srv, the memory associated with it is not freed, causing a memory leak: unreferenced object 0xffff896302b45800 (size 1024): comm "(udev-worker)", pid 222, jiffies 4294894636 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace (crc 6265fd77): [<ffffffff993495ed>] kmalloc_trace+0x29d/0x340 [<ffffffffc0ea4a94>] dm_dmub_sw_init+0xb4/0x450 [amdgpu] [<ffffffffc0ea4e55>] dm_sw_init+0x15/0x2b0 [amdgpu] [<ffffffffc0ba8557>] amdgpu_device_init+0x1417/0x24e0 [amdgpu] [<ffffffffc0bab285>] amdgpu_driver_load_kms+0x15/0x190 [amdgpu] [<ffffffffc0ba09c7>] amdgpu_pci_probe+0x187/0x4e0 [amdgpu] [<ffffffff9968fd1e>] local_pci_probe+0x3e/0x90 [<ffffffff996918a3>] pci_device_probe+0xc3/0x230 [<ffffffff99805872>] really_probe+0xe2/0x480 [<ffffffff99805c98>] __driver_probe_device+0x78/0x160 [<ffffffff99805daf>] driver_probe_device+0x1f/0x90 [<ffffffff9980601e>] __driver_attach+0xce/0x1c0 [<ffffffff99803170>] bus_for_each_dev+0x70/0xc0 [<ffffffff99804822>] bus_add_driver+0x112/0x210 [<ffffffff99807245>] driver_register+0x55/0x100 [<ffffffff990012d1>] do_one_initcall+0x41/0x300 Fix this by freeing dmub_srv after destroying it.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/10c6b90e975358c17856a578419dc449887899c2Patch
- https://git.kernel.org/stable/c/33f649f1b1cea39ed360e6c12bba4fac83118e6ePatch
- https://git.kernel.org/stable/c/541e79265ea7e339a7c4a462feafe9f8f996e04bPatch
- https://git.kernel.org/stable/c/58168005337eabef345a872be3f87d0215ff3b30Patch
- https://git.kernel.org/stable/c/b49b022f7dfce85eb77d0d987008fde5c01d7857Patch
- https://git.kernel.org/stable/c/bae67893578d608e35691dcdfa90c4957debf1d3Patch
- https://git.kernel.org/stable/c/10c6b90e975358c17856a578419dc449887899c2Patch
- https://git.kernel.org/stable/c/33f649f1b1cea39ed360e6c12bba4fac83118e6ePatch
- https://git.kernel.org/stable/c/541e79265ea7e339a7c4a462feafe9f8f996e04bPatch
- https://git.kernel.org/stable/c/58168005337eabef345a872be3f87d0215ff3b30Patch
- https://git.kernel.org/stable/c/b49b022f7dfce85eb77d0d987008fde5c01d7857Patch
- https://git.kernel.org/stable/c/bae67893578d608e35691dcdfa90c4957debf1d3Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.