PT-2024-30729 · Linux+10 · Linux Kernel+10
Zijun Hu
·
Published
2024-07-04
·
Updated
2025-09-29
·
CVE-2024-43871
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.6.50
Description
The issue is related to a memory leakage caused by the driver API
devm free percpu() when used to free memory allocated by devm alloc percpu(). This is fixed by using devres release() instead of devres destroy() within devm free percpu().Recommendations
To resolve the issue, update to Linux kernel version 6.6.50 or later.
As a temporary workaround, consider restricting the use of the
devm free percpu() function until a patch is available.Exploit
Fix
DoS
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu