PT-2024-33702 · Linux+8 · Linux Kernel+8
Published
2024-08-16
·
Updated
2025-09-29
·
CVE-2024-49851
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.58
Description:
A vulnerability in the Linux kernel has been resolved, where the
tpm dev transmit function prepares the TPM space before attempting command transmission. However, if the command fails, no rollback of this preparation is done, resulting in transient handles being leaked if the device is subsequently closed with no further commands performed. The issue is fixed by flushing the space in the event of command transmission failure.Recommendations:
For Linux kernel versions prior to 6.6.58, update to version 6.6.58 or later to resolve the issue. As a temporary workaround, consider implementing a custom rollback mechanism for the
tpm dev transmit function to prevent transient handle leaks until a patch is available.Exploit
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu