CVE-2024-27077 - Missing Release of Memory after Effective Lifetime

Severity

55%

Complexity

18%

Confidentiality

60%

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity The entity->name (i.e. name) is allocated in v4l2_m2m_register_entity but isn't freed in its following error-handling paths. This patch adds such deallocation to prevent memleak of entity->name.

CVSS 3.1 Base Score 5.5. CVSS Attack Vector: local. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

Demo Examples

Missing Release of Memory after Effective Lifetime

CWE-401

The following C function leaks a block of allocated memory if the call to read() does not return the expected number of bytes:


               
}
return buf;
return NULL;
return NULL;

Overview

First reported 9 months ago

2024-05-01 13:15:00

Last updated 1 month ago

2024-12-23 14:38:00

Affected Software

Linux Kernel

References

https://git.kernel.org/stable/c/3dd8abb0ed0e0a7c66d6d677c86ccb188cc39333

https://git.kernel.org/stable/c/0175f2d34c85744f9ad6554f696cf0afb5bd04e4

https://git.kernel.org/stable/c/afd2a82fe300032f63f8be5d6cd6981e75f8bbf2

https://git.kernel.org/stable/c/dc866b69cc51af9b8509b4731b8ce2a4950cd0ef

https://git.kernel.org/stable/c/0c9550b032de48d6a7fa6a4ddc09699d64d9300d

https://git.kernel.org/stable/c/90029b9c979b60de5cb2b70ade4bbf61d561bc5d

https://git.kernel.org/stable/c/5dc319cc3c4f7b74f7dfba349aa26f87efb52458

https://git.kernel.org/stable/c/9c23ef30e840fedc66948299509f6c2777c9cf4f

https://git.kernel.org/stable/c/8f94b49a5b5d386c038e355bef6347298aabd211

https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html

https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html

https://git.kernel.org/stable/c/0175f2d34c85744f9ad6554f696cf0afb5bd04e4

Patch

https://git.kernel.org/stable/c/0c9550b032de48d6a7fa6a4ddc09699d64d9300d

Patch

https://git.kernel.org/stable/c/3dd8abb0ed0e0a7c66d6d677c86ccb188cc39333

Patch

https://git.kernel.org/stable/c/5dc319cc3c4f7b74f7dfba349aa26f87efb52458

Patch

https://git.kernel.org/stable/c/8f94b49a5b5d386c038e355bef6347298aabd211

Patch

https://git.kernel.org/stable/c/90029b9c979b60de5cb2b70ade4bbf61d561bc5d

Patch

https://git.kernel.org/stable/c/9c23ef30e840fedc66948299509f6c2777c9cf4f

Patch

https://git.kernel.org/stable/c/afd2a82fe300032f63f8be5d6cd6981e75f8bbf2

Patch

https://git.kernel.org/stable/c/dc866b69cc51af9b8509b4731b8ce2a4950cd0ef

Patch

https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html

Patch

https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html

Patch

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.