CVE-2024-27077
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity The entity->name (i.e. name) is allocated in v4l2_m2m_register_entity but isn't freed in its following error-handling paths.
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity The entity->name (i.e. name) is allocated in v4l2_m2m_register_entity but isn't freed in its following error-handling paths. This patch adds such deallocation to prevent memleak of entity->name.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.29% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0175f2d34c85744f9ad6554f696cf0afb5bd04e4Patch
- https://git.kernel.org/stable/c/0c9550b032de48d6a7fa6a4ddc09699d64d9300dPatch
- https://git.kernel.org/stable/c/3dd8abb0ed0e0a7c66d6d677c86ccb188cc39333Patch
- https://git.kernel.org/stable/c/5dc319cc3c4f7b74f7dfba349aa26f87efb52458Patch
- https://git.kernel.org/stable/c/8f94b49a5b5d386c038e355bef6347298aabd211Patch
- https://git.kernel.org/stable/c/90029b9c979b60de5cb2b70ade4bbf61d561bc5dPatch
- https://git.kernel.org/stable/c/9c23ef30e840fedc66948299509f6c2777c9cf4fPatch
- https://git.kernel.org/stable/c/afd2a82fe300032f63f8be5d6cd6981e75f8bbf2Patch
- https://git.kernel.org/stable/c/dc866b69cc51af9b8509b4731b8ce2a4950cd0efPatch
- https://git.kernel.org/stable/c/0175f2d34c85744f9ad6554f696cf0afb5bd04e4Patch
- https://git.kernel.org/stable/c/0c9550b032de48d6a7fa6a4ddc09699d64d9300dPatch
- https://git.kernel.org/stable/c/3dd8abb0ed0e0a7c66d6d677c86ccb188cc39333Patch
- https://git.kernel.org/stable/c/5dc319cc3c4f7b74f7dfba349aa26f87efb52458Patch
- https://git.kernel.org/stable/c/8f94b49a5b5d386c038e355bef6347298aabd211Patch
- https://git.kernel.org/stable/c/90029b9c979b60de5cb2b70ade4bbf61d561bc5dPatch
- https://git.kernel.org/stable/c/9c23ef30e840fedc66948299509f6c2777c9cf4fPatch
- https://git.kernel.org/stable/c/afd2a82fe300032f63f8be5d6cd6981e75f8bbf2Patch
- https://git.kernel.org/stable/c/dc866b69cc51af9b8509b4731b8ce2a4950cd0efPatch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlPatch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.htmlPatch
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.