CVE-2024-56564
MEDIUMLinux Kernel 6.10-6.12.3 - Reference Leak in ceph_mds_auth_match
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ceph: pass cred pointer to ceph_mds_auth_match() This eliminates a redundant get_current_cred() call, because ceph_mds_check_access() has already obtained this pointer. As a side effect, this also fixes a reference leak in ceph_mds_auth_match(): by omitting the get_current_cred() call, no additional cred reference is taken.
References (2)
Core 2
Scores
CVSS v3
5.5
EPSS
0.0019
EPSS Percentile
8.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (8)
linux/Kernel
6.10.0 - 6.12.4linux
Linux/Linux
< 6.10
Linux/Linux
596afb0b8933ba6ed7227adcc538db26feb25c74 - 23426309a4064b25a961e1c72961d8bfc7c8c990
Linux/Linux
596afb0b8933ba6ed7227adcc538db26feb25c74 - ffa6ba7bdb7f07f49c9e9150b0176df066520f62
Linux/Linux
6.10
Linux/Linux
6.12.4 - 6.12.*
Linux/Linux
6.13
linux/linux_kernel
6.10 - 6.12.4
Published
Dec 27, 2024
Tracked Since
Feb 18, 2026