CVE-2024-41002
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - Fix memory leak for sec resource release The AIV is one of the SEC resources.
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - Fix memory leak for sec resource release The AIV is one of the SEC resources. When releasing resources, it need to release the AIV resources at the same time. Otherwise, memory leakage occurs. The aiv resource release is added to the sec resource release function.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.27% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/36810d2db3496bb8b4db7ccda666674a5efc7b47Patch
- https://git.kernel.org/stable/c/7c42ce556ff65995c8875c9ed64141c14238e7e6Patch
- https://git.kernel.org/stable/c/9f21886370db451b0fdc651f6e41550a1da70601Patch
- https://git.kernel.org/stable/c/a886bcb0f67d1e3d6b2da25b3519de59098200c2Patch
- https://git.kernel.org/stable/c/bba4250757b4ae1680fea435a358d8093f254094Patch
- https://git.kernel.org/stable/c/36810d2db3496bb8b4db7ccda666674a5efc7b47Patch
- https://git.kernel.org/stable/c/7c42ce556ff65995c8875c9ed64141c14238e7e6Patch
- https://git.kernel.org/stable/c/9f21886370db451b0fdc651f6e41550a1da70601Patch
- https://git.kernel.org/stable/c/a886bcb0f67d1e3d6b2da25b3519de59098200c2Patch
- https://git.kernel.org/stable/c/bba4250757b4ae1680fea435a358d8093f254094Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.