CVE-2024-0443
בינונית 5.5
תיאור (מקור, אנגלית)
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error.
מדדים
- CVSS 3.1
-
5.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-25/7/2026
- CWE
- CWE-402, CWE-668
מוצרים מושפעים
linux: linux kernel; redhat: enterprise linux; fedoraproject: fedora
קישורים
- https://access.redhat.com/errata/RHSA-2023:6583
- https://access.redhat.com/errata/RHSA-2023:7077 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7370
- https://access.redhat.com/security/cve/CVE-2024-0443 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2257968 Issue TrackingThird Party Advisory
- https://lore.kernel.org/linux-block/[email protected]/ Mailing List
- https://access.redhat.com/errata/RHSA-2023:6583
- https://access.redhat.com/errata/RHSA-2023:7077 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7370
- https://access.redhat.com/security/cve/CVE-2024-0443 Third Party Advisory