Wind River Support Network

HomeDefectsLIN1022-7972
Fixed

LIN1022-7972 : Security Advisory - linux - CVE-2024-26993

Created: May 5, 2024    Updated: May 6, 2024
Resolved Date: May 6, 2024
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

fs: sysfs: Fix reference leak in sysfs_break_active_protection()

The sysfs_break_active_protection() routine has an obvious reference
leak in its error path.  If the call to kernfs_find_and_get() fails then
kn will be NULL, so the companion sysfs_unbreak_active_protection()
routine won't get called (and would only cause an access violation by
trying to dereference kn->parent if it was called).  As a result, the
reference to kobj acquired at the start of the function will never be
released.

Fix the leak by adding an explicit kobject_put() call when kn is NULL.

CREATE(Triage):(User=admin) CVE-2024-26993 (https://nvd.nist.gov/vuln/detail/CVE-2024-26993)

CVEs


Live chat
Online