#VU93746 Improper resource shutdown or release in Linux kernel


Published: 2024-07-04

Vulnerability identifier: #VU93746

Vulnerability risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-35951

CWE-ID: CWE-404

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to failure to properly release resources within the panfrost_mmu_map_fault_addr() and sg_free_table() functions in drivers/gpu/drm/panfrost/panfrost_mmu.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/31806711e8a4b75e09b1c43652f2a6420e6e1002
http://git.kernel.org/stable/c/e18070c622c63f0cab170348e320454728c277aa
http://git.kernel.org/stable/c/1fc9af813b25e146d3607669247d0f970f5a87c3
http://www.openwall.com/lists/oss-security/2024/05/30/2
http://www.openwall.com/lists/oss-security/2024/05/30/1


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability