SB20240610103 - Memory leak in Linux kernel dma idxd driver
Published: June 10, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2021-46917)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to memory leak within the disable_wq() function in drivers/dma/idxd/sysfs.c, within the idxd_wq_drain(), idxd_wq_unmap_portal(), idxd_wq_disable_cleanup() and idxd_wq_config_write() functions in drivers/dma/idxd/device.c. A local user can gain access to sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/e5eb9757fe4c2392e069246ae78badc573af1833
- https://git.kernel.org/stable/c/f7dc8f5619165e1fa3383d0c2519f502d9e2a1a9
- https://git.kernel.org/stable/c/ea9aadc06a9f10ad20a90edc0a484f1147d88a7a
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.32
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.16
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12