Wind River Support Network

HomeDefectsLIN1023-6638
Fixed

LIN1023-6638 : Security Advisory - linux - CVE-2024-38554

Created: Jun 19, 2024    Updated: Jul 2, 2024
Resolved Date: Jun 27, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.12
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

ax25: Fix reference count leak issue of net_device

There is a reference count leak issue of the object "net_device" in
ax25_dev_device_down(). When the ax25 device is shutting down, the
ax25_dev_device_down() drops the reference count of net_device one
or zero times depending on if we goto unlock_put or not, which will
cause memory leak.

In order to solve the above issue, decrease the reference count of
net_device after dev->ax25_ptr is set to null.

CREATE(Triage):(User=admin) CVE-2024-38554 (https://nvd.nist.gov/vuln/detail/CVE-2024-38554)

CVEs


Live chat
Online