Bug 2263881 (CVE-2024-25740)

Summary: CVE-2024-25740 kernel: memory leak in ubi driver
Product: [Other] Security Response Reporter: ybuenos
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: acaringi, allarkin, aquini, bhu, chwhite, cye, cyin, darcari, dbohanno, debarbos, dfreiber, drow, dvlasenk, ezulian, hkrzesin, jarod, jburrell, jdenham, jfaracco, jforbes, jlelli, joe.lawrence, jshortt, jstancek, jwyatt, kcarcia, ldoskova, lgoncalv, lzampier, mleitner, mmilgram, mstowell, nmurray, ptalbert, rkeshri, rogbas, rparrazo, rrobaina, rvrbovsk, rysulliv, scweaver, sukulkar, tglozar, tyberry, vkumar, wcosta, williams, wmealing, ycote, ykopkova, zhijwang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the UBI driver in the Linux kernel. When processing an ioctl call for UBI_IOCATT, allocated memory for kobj->name is not released in case of an error, resulting in a memory leak.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2263888    
Bug Blocks: 2263882    

Description ybuenos 2024-02-12 15:12:42 UTC
A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released.

Reference:
https://lore.kernel.org/lkml/0171b6cc-95ee-3538-913b-65a391a446b3%40huawei.com/T/

Comment 3 ybuenos 2024-02-12 15:52:48 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 2263888]

Comment 7 David Arcari 2024-07-19 14:51:43 UTC
There is no fix for this.  

Furthermore it doesn't seem to meet the criteria for moderate.  It doesn't seem as if this is something that can be exploited.  Can we get this reduced to minor?

Comment 8 ybuenos 2024-07-21 19:19:52 UTC
Tagging @rkeshri for the above question