CVE-2024-56564

MEDIUM

Linux Kernel 6.10-6.12.3 - Reference Leak in ceph_mds_auth_match

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ceph: pass cred pointer to ceph_mds_auth_match() This eliminates a redundant get_current_cred() call, because ceph_mds_check_access() has already obtained this pointer. As a side effect, this also fixes a reference leak in ceph_mds_auth_match(): by omitting the get_current_cred() call, no additional cred reference is taken.

Scores

CVSS v3 5.5
EPSS 0.0019
EPSS Percentile 8.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (8)
linux/Kernel 6.10.0 - 6.12.4linux
Linux/Linux < 6.10
Linux/Linux 596afb0b8933ba6ed7227adcc538db26feb25c74 - 23426309a4064b25a961e1c72961d8bfc7c8c990
Linux/Linux 596afb0b8933ba6ed7227adcc538db26feb25c74 - ffa6ba7bdb7f07f49c9e9150b0176df066520f62
Linux/Linux 6.10
Linux/Linux 6.12.4 - 6.12.*
Linux/Linux 6.13
linux/linux_kernel 6.10 - 6.12.4
Published Dec 27, 2024
Tracked Since Feb 18, 2026