devres: Fix memory leakage caused by driver API devm_free_percpu()
Published Aug 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
It will cause memory leakage when use driver API devm_free_percpu() to free memory allocated by devm_alloc_percpu(), fixed by using devres_release() instead of devres_destroy() within devm_free_percpu().
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 4.10
Unaffected
- ≥ 0, < 4.10
- ≥ 4.19.320, ≤ 4.19.*
- ≥ 5.10.224, ≤ 5.10.*
- ≥ 5.15.165, ≤ 5.15.*
- ≥ 5.4.282, ≤ 5.4.*
- ≥ 6.1.103, ≤ 6.1.*
- ≥ 6.10.3, ≤ 6.10.*
- 6.11
- ≥ 6.6.44, ≤ 6.6.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 4.10 · < 4.19.320
- ≥ 4.20 · < 5.4.282
- ≥ 5.5 · < 5.10.224
- ≥ 5.11 · < 5.15.165
- ≥ 5.16 · < 6.1.103
- ≥ 6.2 · < 6.6.44
- ≥ 6.7 · < 6.10.3
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.22.1.el8_10
Fixed · RHSA-2024:7000
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
Fixed · RHSA-2024:7001
Red Hat Enterprise Linux 9
kernel-0:5.14.0-570.12.1.el9_6
Fixed · RHSA-2025:6966
Red Hat Enterprise Linux 9
kernel-0:5.14.0-570.12.1.el9_6
Fixed · RHSA-2025:6966
Red Hat Enterprise Linux 9.4 Extended Update Support
kernel-0:5.14.0-427.67.1.el9_4
Fixed · RHSA-2025:4509
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.22.1.el8_10 | Fixed | RHSA-2024:7000 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10 | Fixed | RHSA-2024:7001 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-570.12.1.el9_6 | Fixed | RHSA-2025:6966 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-570.12.1.el9_6 | Fixed | RHSA-2025:6966 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | kernel-0:5.14.0-427.67.1.el9_4 | Fixed | RHSA-2025:4509 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (20)
- https://access.redhat.com/security/cve/CVE-2024-43871 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2306365 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-355557.html
- https://cert-portal.siemens.com/productcert/html/ssa-398330.html
- https://cert-portal.siemens.com/productcert/html/ssa-613116.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-40521 Advisory
- https://git.kernel.org/stable/c/3047f99caec240a88ccd06197af2868da1af6a96 Patch
- https://git.kernel.org/stable/c/3dcd0673e47664bc6c719ad47dadac6d55d5950d Patch
- https://git.kernel.org/stable/c/700e8abd65b10792b2f179ce4e858f2ca2880f85 Patch
- https://git.kernel.org/stable/c/95065edb8ebb27771d5f1e898eef6ab43dc6c87c Patch
- https://git.kernel.org/stable/c/b044588a16a978cd891cb3d665dd7ae06850d5bf Patch
- https://git.kernel.org/stable/c/b67552d7c61f52f1271031adfa7834545ae99701 Patch
- https://git.kernel.org/stable/c/bd50a974097bb82d52a458bd3ee39fb723129a0c Patch
- https://git.kernel.org/stable/c/ef56dcdca8f2a53abc3a83d388b8336447533d85 Patch
- https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lore.kernel.org/linux-cve-announce/2024082136-CVE-2024-43871-c2cd@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-43871
- https://www.cve.org/CVERecord?id=CVE-2024-43871
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data