CVE-2024-35858

MEDIUM

Linux Kernel 6.6-6.6.29, 6.7-6.8.8 - Use-After-Free in bcmasp TX Ring Cleanup

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix memory leak when bringing down interface When bringing down the TX rings we flush the rings but forget to reclaimed the flushed packets. This leads to a memory leak since we do not free the dma mapped buffers. This also leads to tx control block corruption when bringing down the interface for power management.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (12)
linux/Kernel 6.6.0 - 6.6.30linux
linux/Kernel 6.7.0 - 6.8.9linux
Linux/Linux < 6.6
Linux/Linux 490cb412007de593e07c1d3e2b1ec4233886707c - 09040baf8779ad880e0e0d0ea10e57aa929ef3ab
Linux/Linux 490cb412007de593e07c1d3e2b1ec4233886707c - 2389ad1990163d29cba5480d693b4c2e31cc545c
Linux/Linux 490cb412007de593e07c1d3e2b1ec4233886707c - 9f898fc2c31fbf0ac5ecd289f528a716464cb005
Linux/Linux 6.6
Linux/Linux 6.6.30 - 6.6.*
Linux/Linux 6.8.9 - 6.8.*
Linux/Linux 6.9
... and 2 more
Published May 17, 2024
Tracked Since Feb 18, 2026