Executive brief
A vulnerability in the Linux kernel's device resource management system can lead to memory leaks. This occurs when specific driver functions fail to properly release memory, potentially allowing a local user to exhaust system resources. Over time, this could lead to system instability or a complete crash, impacting the availability of services running on the affected machine.
Technical details
A memory leak vulnerability exists in the Linux kernel's devres (device resource management) subsystem. The root cause is the incorrect use of devres_destroy() instead of devres_release() within the devm_free_percpu() function. While devres_destroy() removes the resource from the managed list, it does not actually trigger the release handler to free the underlying per-CPU memory, leading to a leak every time the API is called. A local attacker with the ability to trigger driver-related memory allocation and deallocation cycles could exhaust system memory, resulting in a denial of service (DoS). The issue has been patched in various stable branches by updating devm_free_percpu() to use devres_release().
Affected products
- Linux Linux Kernel 4.10 to 4.19.319, 4.20 to 5.4.281, 5.5 to 5.10.223, 5.11 to 5.15.164, 5.16 to 6.1.102, 6.2 to 6.6.43, 6.7 to 6.10.2
Timeline
- 2024-08-21: disclosed: Initial publication of the CVE record.
- 2024-08-19: patched: Fix committed to the Linux kernel stable tree.
References
- https://git.kernel.org/stable/c/3047f99caec240a88ccd06197af2868da1af6a96
- https://git.kernel.org/stable/c/3dcd0673e47664bc6c719ad47dadac6d55d5950d
- https://git.kernel.org/stable/c/700e8abd65b10792b2f179ce4e858f2ca2880f85
- https://git.kernel.org/stable/c/95065edb8ebb27771d5f1e898eef6ab43dc6c87c
- https://git.kernel.org/stable/c/b044588a16a978cd891cb3d665dd7ae06850d5bf
- https://git.kernel.org/stable/c/b67552d7c61f52f1271031adfa7834545ae99701
- https://git.kernel.org/stable/c/bd50a974097bb82d52a458bd3ee39fb723129a0c