PT-2024-33899 · Linux+6 · Linux Kernel+6
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.58
Description:
The issue is related to memory leakage in the zram device when it has multi-streams and is reset without freeing secondary algorithms names. This can be resolved by using kfree() to free the secondary algorithms names. The estimated number of potentially affected devices is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations:
For Linux kernel versions prior to 6.6.58, update to version 6.6.58 or later to resolve the issue. As a temporary workaround, consider implementing a custom solution to free secondary algorithms names when resetting the zram device to prevent memory leakage.
Exploit
Fix
DoS
Memory Leak
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu