CVE-2024-38602
Published: Jun 19, 2024
Modified: May 23, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ax25: Fix reference count leak issues of ax25_dev The ax25_addr_ax25dev() and ax25_dev_device_down() exist a reference count leak issue of the object "ax25_dev". Memory leak issue in ax25_addr_ax25dev(): The reference count of the object "ax25_dev" can be increased multiple times in ax25_addr_ax25dev(). This will cause a memory leak. Memory leak issues in ax25_dev_device_down(): The reference count of ax25_dev is set to 1 in ax25_dev_device_up() and then increase the reference count when ax25_dev is added to ax25_dev_list. As a result, the reference count of ax25_dev is 2. But when the device is shutting down. The ax25_dev_device_down() drops the reference count once or twice depending on if we goto unlock_put or not, which will cause memory leak. As for the issue of ax25_addr_ax25dev(), it is impossible for one pointer to be on a list twice. So add a break in ax25_addr_ax25dev(). As for the issue of ax25_dev_device_down(), increase the reference count of ax25_dev once in ax25_dev_device_up() and decrease the reference count of ax25_dev after it is removed from the ax25_dev_list.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected d01ffb9eee4af165d83b08dd73ebdf9fe94a519b - < ae467750a3765dd1092eb29f58247950a2f9b60caffected d01ffb9eee4af165d83b08dd73ebdf9fe94a519b - < 38eb01edfdaa1562fa00429be2e33f45383b1b3aaffected d01ffb9eee4af165d83b08dd73ebdf9fe94a519b - < 81d8240b0a243b3ddd8fa8aa172f1acc2f7cc8f3affected d01ffb9eee4af165d83b08dd73ebdf9fe94a519b - < 1ea02699c7557eeb35ccff2bd822de1b3e09d868affected d01ffb9eee4af165d83b08dd73ebdf9fe94a519b - < b505e0319852b08a3a716b64620168eab21f4ced+10 more versions |
Linux | Linux | affected 5.17unaffected 0 - < 5.17unaffected 6.1.93 - <= 6.1.*unaffected 6.6.33 - <= 6.6.*unaffected 6.8.12 - <= 6.8.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now