Executive brief
A vulnerability exists in the Linux kernel's power management component for processors. When certain CPU power-saving features are disabled or removed, the system fails to properly release allocated memory. Over time, this could lead to a memory leak that degrades system performance or causes stability issues.
Technical details
A memory leak vulnerability was identified in drivers/acpi/processor_idle.c within the Linux kernel. The root cause is located in the acpi_processor_power_exit() function, which fails to call kfree() on the CPU idle device object after it has been unregistered. This occurs during the teardown phase of the ACPI processor driver. An attacker with high privileges could potentially trigger this leak repeatedly to exhaust system memory, impacting availability. The issue has been resolved in multiple stable branches of the Linux kernel by ensuring the device memory is explicitly freed.
Affected products
- Linux Linux Kernel 3.7 to 4.19.311, 4.20 to 5.4.273, 5.5 to 5.10.214, 5.11 to 5.15.153, 5.16 to 6.1.83, 6.2 to 6.6.23, 6.7 to 6.7.11, 6.8 to 6.8.2
Timeline
- 2024-02-13: other: Patch authored
- 2024-04-17: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1cbaf4c793b0808532f4e7b40bc4be7cec2c78f2
- https://git.kernel.org/stable/c/3d48e5be107429ff5d824e7f2a00d1b610d36fbc
- https://git.kernel.org/stable/c/8d14a4d0afb49a5b8535d414c782bb334860e73e
- https://git.kernel.org/stable/c/c2a30c81bf3cb9033fa9f5305baf7c377075e2e5
- https://git.kernel.org/stable/c/cd5c2d0b09d5b6d3f0a7bbabe6761a4997e9dee9
- https://git.kernel.org/stable/c/d351bcadab6caa6d8ce7159ff4b77e2da35c09fa
- https://git.kernel.org/stable/c/e18afcb7b2a12b635ac10081f943fcf84ddacc51