Bug 2263881 (CVE-2024-25740) - CVE-2024-25740 kernel: memory leak in ubi driver
Summary: CVE-2024-25740 kernel: memory leak in ubi driver
Keywords:
Status: NEW
Alias: CVE-2024-25740
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2263888
Blocks: 2263882
TreeView+ depends on / blocked
 
Reported: 2024-02-12 15:12 UTC by ybuenos
Modified: 2024-08-07 17:27 UTC (History)
51 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description ybuenos 2024-02-12 15:12:42 UTC
A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released.

Reference:
https://lore.kernel.org/lkml/0171b6cc-95ee-3538-913b-65a391a446b3%40huawei.com/T/

Comment 3 ybuenos 2024-02-12 15:52:48 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 2263888]

Comment 7 David Arcari 2024-07-19 14:51:43 UTC
There is no fix for this.  

Furthermore it doesn't seem to meet the criteria for moderate.  It doesn't seem as if this is something that can be exploited.  Can we get this reduced to minor?

Comment 8 ybuenos 2024-07-21 19:19:52 UTC
Tagging @rkeshri for the above question


Note You need to log in before you can comment on or make changes to this bug.