We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-39493

crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak



Description

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak Using completion_done to determine whether the caller has gone away only works after a complete call. Furthermore it's still possible that the caller has not yet called wait_for_completion, resulting in another potential UAF. Fix this by making the caller use cancel_work_sync and then freeing the memory safely.

Reserved 2024-06-25 | Published 2024-07-10 | Updated 2024-12-19 | Assigner Linux

Product status

Default status
unaffected

daba62d9eeddcc5b1081be7d348ca836c83c59d7 before 0ce5964b82f212f4df6a9813f09a0b5de15bd9c8
affected

8e81cd58aee14a470891733181a47d123193ba81 before 6396b33e98c096bff9c253ed49c008247963492a
affected

d03092550f526a79cf1ade7f0dfa74906f39eb71 before a718b6d2a329e069b27d9049a71be5931e71d960
affected

4ae5a97781ce7d6ecc9c7055396535815b64ca4f before 3fb4601e0db10d4fe25e46f3fa308d40d37366bd
affected

226fc408c5fcd23cc4186f05ea3a09a7a9aef2f7 before e7428e7e3fe94a5089dc12ffe5bc31574d2315ad
affected

8a5a7611ccc7b1fba8d933a9f22a2e76859d94dc before c2d443aa1ae3175c13a665f3a24b8acd759ce9c3
affected

7d42e097607c4d246d99225bf2b195b6167a210c before d0fd124972724cce0d48b9865ce3e273ef69e246
affected

7d42e097607c4d246d99225bf2b195b6167a210c before d3b17c6d9dddc2db3670bc9be628b122416a3d26
affected

Default status
affected

6.9
affected

Any version before 6.9
unaffected

4.19.316
unaffected

5.4.278
unaffected

5.10.219
unaffected

5.15.161
unaffected

6.1.94
unaffected

6.6.34
unaffected

6.9.5
unaffected

6.10
unaffected

References

git.kernel.org/...c/0ce5964b82f212f4df6a9813f09a0b5de15bd9c8

git.kernel.org/...c/6396b33e98c096bff9c253ed49c008247963492a

git.kernel.org/...c/a718b6d2a329e069b27d9049a71be5931e71d960

git.kernel.org/...c/3fb4601e0db10d4fe25e46f3fa308d40d37366bd

git.kernel.org/...c/e7428e7e3fe94a5089dc12ffe5bc31574d2315ad

git.kernel.org/...c/c2d443aa1ae3175c13a665f3a24b8acd759ce9c3

git.kernel.org/...c/d0fd124972724cce0d48b9865ce3e273ef69e246

git.kernel.org/...c/d3b17c6d9dddc2db3670bc9be628b122416a3d26

cve.org (CVE-2024-39493)

nvd.nist.gov (CVE-2024-39493)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-39493

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.