PT-2024-31336 · Linux+7 · Linux Kernel+7
Published
2024-07-01
·
Updated
2026-03-14
·
CVE-2024-44969
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.6.50
Description
The issue occurs when a task waiting for completion of a Store Data operation is interrupted, and an attempt to halt this operation fails due to a hardware or firmware problem. This can lead to the SCLP facility storing data into buffers referenced by the original operation at a later time, potentially resulting in a memory leak. The situation is handled by not releasing the referenced data buffers if the halt attempt fails. For current use cases, this might result in a leak of a few pages of memory in case of a rare hardware/firmware malfunction.
Recommendations
Update to Linux kernel version 6.6.50 or later to resolve the issue. As a temporary workaround, consider implementing measures to minimize the risk of memory leaks, such as monitoring system resources and adjusting configuration settings to reduce the likelihood of interrupted Store Data operations.
Exploit
Fix
Memory Leak
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu