5.5

CVE-2024-26829

media: ir_toy: fix a memleak in irtoy_tx

In the Linux kernel, the following vulnerability has been resolved:

media: ir_toy: fix a memleak in irtoy_tx

When irtoy_command fails, buf should be freed since it is allocated by
irtoy_tx, or there is a memleak.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 5.10.210
LinuxLinux Kernel Version >= 5.15.54 < 5.15.149
LinuxLinux Kernel Version >= 5.16 < 6.1.79
LinuxLinux Kernel Version >= 6.2 < 6.6.18
LinuxLinux Kernel Version >= 6.7 < 6.7.6
LinuxLinux Kernel Version6.8 Updaterc1
LinuxLinux Kernel Version6.8 Updaterc2
LinuxLinux Kernel Version6.8 Updaterc3
LinuxLinux Kernel Version6.8 Updaterc4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.133
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://git.kernel.org/stable/c/207557e393a135c1b6fe1df7cc0741d2c1789fff
Patch
https://git.kernel.org/stable/c/486a4176bc783df798bce2903824801af8d2c3ae
Patch
https://git.kernel.org/stable/c/7219a692ffc00089015ada33b85b334d1a4b6e8e
Patch
https://git.kernel.org/stable/c/b37259448bbc70af1d0e52a9dd5559a9c29c9621
Patch
https://git.kernel.org/stable/c/be76ad74a43f90f340f9f479e6b04f02125f6aef
Patch
https://git.kernel.org/stable/c/dc9ceb90c4b42c6e5c6757df1d6257110433788e
Patch