CVE-2024-35882

I

n the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a slow server-side memory leak with RPC-over-TCP Jan Schunk reports that his small NFS servers suffer from memory exhaustion after just a few days. A bisect shows that commit e18e157bb5c8 ("SUNRPC: Send RPC message on TCP with a single sock_sendmsg() call") is the first bad commit. That commit assumed that sock_sendmsg() releases all the pages in the underlying bio_vec array, but the reality is that it doesn't. svc_xprt_release() releases the rqst's response pages, but the record marker page fragment isn't one of those, so it is never released. This is a narrow fix that can be applied to stable kernels. A more extensive fix is in the works.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*

History

05 Mar 2025, 17:40

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-401
References () https://git.kernel.org/stable/c/05258a0a69b3c5d2c003f818702c0a52b6fea861 - () https://git.kernel.org/stable/c/05258a0a69b3c5d2c003f818702c0a52b6fea861 - Patch, Mailing List
References () https://git.kernel.org/stable/c/1ba1291172f935e6b6fe703161a948f3347400b8 - () https://git.kernel.org/stable/c/1ba1291172f935e6b6fe703161a948f3347400b8 - Patch, Mailing List
References () https://git.kernel.org/stable/c/a2ebedf7bcd17a1194a0a18122c885eb578ee882 - () https://git.kernel.org/stable/c/a2ebedf7bcd17a1194a0a18122c885eb578ee882 - Patch, Mailing List

21 Nov 2024, 09:21

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/05258a0a69b3c5d2c003f818702c0a52b6fea861 - () https://git.kernel.org/stable/c/05258a0a69b3c5d2c003f818702c0a52b6fea861 -
References () https://git.kernel.org/stable/c/1ba1291172f935e6b6fe703161a948f3347400b8 - () https://git.kernel.org/stable/c/1ba1291172f935e6b6fe703161a948f3347400b8 -
References () https://git.kernel.org/stable/c/a2ebedf7bcd17a1194a0a18122c885eb578ee882 - () https://git.kernel.org/stable/c/a2ebedf7bcd17a1194a0a18122c885eb578ee882 -
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: Revertir "drm/amd/display: Enviar mensaje de desactivación DTBCLK en la primera confirmación" Esto revierte la confirmación f341055b10bd8be55c3c995dff5f770b236b8ca9. Se observó un bloqueo del sistema; se cree que este compromiso es el punto de regresión.

19 May 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-19 09:15

Updated : 2025-03-05 17:40


NVD link : CVE-2024-35882

Mitre link : CVE-2024-35882

CVE.ORG link : CVE-2024-35882


JSON object : View

Products Affected
CWE
CWE-401

Missing Release of Memory after Effective Lifetime