5.5
CVE-2024-26993
- EPSS 0.01%
- Published 01.05.2024 06:15:17
- Last modified 04.11.2025 18:16:08
- Source 416baaa9-dc9f-4396-8d5f-8c081f
- CVE-Watchlists
- Open
In the Linux kernel, the following vulnerability has been resolved: fs: sysfs: Fix reference leak in sysfs_break_active_protection() The sysfs_break_active_protection() routine has an obvious reference leak in its error path. If the call to kernfs_find_and_get() fails then kn will be NULL, so the companion sysfs_unbreak_active_protection() routine won't get called (and would only cause an access violation by trying to dereference kn->parent if it was called). As a result, the reference to kobj acquired at the start of the function will never be released. Fix the leak by adding an explicit kobject_put() call when kn is NULL.
Data is provided by the National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.16.62 < 3.17
Linux ≫ Linux Kernel Version >= 3.18.121 < 3.19
Linux ≫ Linux Kernel Version >= 4.4.154 < 4.5
Linux ≫ Linux Kernel Version >= 4.9.125 < 4.10
Linux ≫ Linux Kernel Version >= 4.14.68 < 4.15
Linux ≫ Linux Kernel Version >= 4.18.6 < 4.19
Linux ≫ Linux Kernel Version >= 4.19 < 5.15.157
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.88
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.29
Linux ≫ Linux Kernel Version >= 6.7 < 6.8.8
Linux ≫ Linux Kernel Version6.9 Updaterc1
Linux ≫ Linux Kernel Version6.9 Updaterc2
Linux ≫ Linux Kernel Version6.9 Updaterc3
Linux ≫ Linux Kernel Version6.9 Updaterc4
| Type | Source | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.019 |
| Source | Base Score | Exploit Score | Impact Score | Vector string |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|