PT-2024-8484 · Linux+4 · Linux Kernel+4

Published

2024-04-19

·

Updated

2024-12-30

·

CVE-2024-35858

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description The issue is related to a memory leak in the Linux kernel's bcmasp component when bringing down the interface. This occurs because the flushed packets are not reclaimed, leading to a memory leak since the dma mapped buffers are not freed. Additionally, this can cause tx control block corruption when bringing down the interface for power management. The vulnerability can be exploited to cause a denial of service.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.37 or later. As a temporary workaround, consider disabling the interface for power management until a patch is available. Restrict access to the vulnerable bcmasp component to minimize the risk of exploitation. Avoid using the affected interface until the issue is resolved.

Exploit

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10044
CVE-2024-35858
MGASA-2024-0263
MGASA-2024-0266
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu