CVE-2024-36956

MEDIUM

Linux Kernel 6.8-6.8.9 - Memory Leak in Thermal Zone Debug Memory Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Free all thermal zone debug memory on zone removal Because thermal_debug_tz_remove() does not free all memory allocated for thermal zone diagnostics, some of that memory becomes unreachable after freeing the thermal zone's struct thermal_debugfs object. Address this by making thermal_debug_tz_remove() free all of the memory in question. Cc :6.8+ <[email protected]> # 6.8+

Scores

CVSS v3 5.5
EPSS 0.0019
EPSS Percentile 9.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (9)
linux/Kernel 6.8.0 - 6.8.10linux
Linux/Linux < 6.8
Linux/Linux 6.8
Linux/Linux 6.8.10 - 6.8.*
Linux/Linux 6.9
Linux/Linux 7ef01f228c9f54c6260319858be138a8a7e9e704 - 72c1afffa4c645fe0e0f1c03e5f34395ed65b5f4
Linux/Linux 7ef01f228c9f54c6260319858be138a8a7e9e704 - f51564e4b3992b53df79460ed5781a5330b5b1d5
linux/linux_kernel 6.9 rc1 (6 CPE variants)
linux/linux_kernel 6.8 - 6.8.10
Published May 30, 2024
Tracked Since Feb 18, 2026