PT-2024-30773 · Linux+5 · Linux Kernel+5
Published
2024-06-04
·
Updated
2026-03-13
·
CVE-2024-43913
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.10.4
Description
The issue is related to the Linux kernel's NVMe driver, specifically the apple driver, which had a problem with device reference counting. This was caused by the driver not calling
nvme uninit ctrl after a successful nvme init ctrl, leading to a leak of the controller device memory on a tagset failure. The impact of this issue could be potential system instability or crashes.Recommendations
To resolve the issue, upgrade the Linux kernel to a version newer than 6.10.4. As a temporary workaround, consider restricting access to the vulnerable NVMe driver until a patch is available.
Exploit
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu