5.5

CVE-2024-50168

net/sun3_82586: fix potential memory leak in sun3_82586_send_packet()

In the Linux kernel, the following vulnerability has been resolved:

net/sun3_82586: fix potential memory leak in sun3_82586_send_packet()

The sun3_82586_send_packet() returns NETDEV_TX_OK without freeing skb
in case of skb->len being too long, add dev_kfree_skb() to fix it.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.6.12 < 4.19.323
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.285
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.229
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.170
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.115
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.59
Linux ≫ Linux Kernel Version >= 6.7 < 6.11.6
Linux ≫ Linux Kernel Version 6.12 Update rc1
Linux ≫ Linux Kernel Version 6.12 Update rc2
Linux ≫ Linux Kernel Version 6.12 Update rc3
Linux ≫ Linux Kernel Version 6.12 Update rc4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.124
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://git.kernel.org/stable/c/137010d26dc5cd47cd62fef77cbe952d31951b7a
Patch
https://git.kernel.org/stable/c/1a17a4ac2d57102497fac53b53c666dba6a0c20d
Patch
https://git.kernel.org/stable/c/2cb3f56e827abb22c4168ad0c1bbbf401bb2f3b8
Patch
https://git.kernel.org/stable/c/6dc937a3086e344f965ca5c459f8f3eb6b68d890
Patch
https://git.kernel.org/stable/c/84f2bac74000dbb7a177d9b98a17031ec8d07ec5
Patch
https://git.kernel.org/stable/c/8d5b20fbc548650019afa96822b6a33ea4ec8aa5
Patch
https://git.kernel.org/stable/c/9c6ce55e6f0bd1541f112833006b4052614c7d94
Patch
https://git.kernel.org/stable/c/db755e55349045375c5c7036e8650afb3ff419d8
Patch
https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html