PT-2024-30773 · Linux+5 · Linux Kernel+5

Published

2024-06-04

·

Updated

2026-03-13

·

CVE-2024-43913

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.10.4
Description The issue is related to the Linux kernel's NVMe driver, specifically the apple driver, which had a problem with device reference counting. This was caused by the driver not calling nvme uninit ctrl after a successful nvme init ctrl, leading to a leak of the controller device memory on a tagset failure. The impact of this issue could be potential system instability or crashes.
Recommendations To resolve the issue, upgrade the Linux kernel to a version newer than 6.10.4. As a temporary workaround, consider restricting access to the vulnerable NVMe driver until a patch is available.

Exploit

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2025-12647
AZL-48632
AZL-48689
BDU:2025-02937
CVE-2024-43913
ECHO-D906-401F-A7F7
OESA-2024-2124
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0557-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7196-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu