Junglewise Threat Intelligence

CVE-2024-43871: Linux Kernel memory leak in devres devm_free_percpu

CVE-2024-43871 · Severity: medium · CVSS 5.5 · Published 2024-08-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's device resource management system can lead to memory leaks. This occurs when specific driver functions fail to properly release memory, potentially allowing a local user to exhaust system resources. Over time, this could lead to system instability or a complete crash, impacting the availability of services running on the affected machine.

Technical details

A memory leak vulnerability exists in the Linux kernel's devres (device resource management) subsystem. The root cause is the incorrect use of devres_destroy() instead of devres_release() within the devm_free_percpu() function. While devres_destroy() removes the resource from the managed list, it does not actually trigger the release handler to free the underlying per-CPU memory, leading to a leak every time the API is called. A local attacker with the ability to trigger driver-related memory allocation and deallocation cycles could exhaust system memory, resulting in a denial of service (DoS). The issue has been patched in various stable branches by updating devm_free_percpu() to use devres_release().

Affected products

  • Linux Linux Kernel 4.10 to 4.19.319, 4.20 to 5.4.281, 5.5 to 5.10.223, 5.11 to 5.15.164, 5.16 to 6.1.102, 6.2 to 6.6.43, 6.7 to 6.10.2

Timeline

  • 2024-08-21: disclosed: Initial publication of the CVE record.
  • 2024-08-19: patched: Fix committed to the Linux kernel stable tree.

References

Related threats