PT-2023-8295 · Linux+2 · Linux Kernel+2

Jay Shin

+1

·

Published

2023-11-07

·

Updated

2024-05-20

·

CVE-2024-0443

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw was found in the blkgs destruction path in block/blk-cgroup.c, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup rstat flush() is only called at css release work fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with local access to cause system instability, such as an out of memory error.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Leak

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00379
CESA-2023_7077
CVE-2024-0443
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023:7370
RHSA-2023_6583
RHSA-2023_7077

Affected Products

Centos
Linux Kernel
Red Hat