PT-2024-26812 · Linux+6 · Linux Kernel+6

Published

2024-04-05

·

Updated

2025-09-29

·

CVE-2024-35972

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak issue has been identified in the Linux kernel, specifically in the bnxt rdma aux device init() function. The leak occurs when ulp = kzalloc() fails, causing the allocated edev to not be properly assigned, which in turn prevents the cleanup path from freeing it. This issue is resolved by assigning the allocated edev properly immediately after allocation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-11524
ALT-PU-2024-13979
ALT-PU-2024-14046
ALT-PU-2024-7511
ALT-PU-2024-9131
AZL-42204
BDU:2025-03075
CVE-2024-35972
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
USN-6893-1
USN-6893-2
USN-6893-3
USN-6918-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu