| { |
| "containers": { |
| "cna": { |
| "providerMetadata": { |
| "orgId": "f4215fc3-5b6b-47ff-a258-f7189bd81038" |
| }, |
| "descriptions": [ |
| { |
| "lang": "en", |
| "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: sysfs: Fix reference leak in sysfs_break_active_protection()\n\nThe sysfs_break_active_protection() routine has an obvious reference\nleak in its error path. If the call to kernfs_find_and_get() fails then\nkn will be NULL, so the companion sysfs_unbreak_active_protection()\nroutine won't get called (and would only cause an access violation by\ntrying to dereference kn->parent if it was called). As a result, the\nreference to kobj acquired at the start of the function will never be\nreleased.\n\nFix the leak by adding an explicit kobject_put() call when kn is NULL." |
| } |
| ], |
| "affected": [ |
| { |
| "product": "Linux", |
| "vendor": "Linux", |
| "defaultStatus": "unaffected", |
| "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", |
| "programFiles": [ |
| "fs/sysfs/file.c" |
| ], |
| "versions": [ |
| { |
| "version": "2afc9166f79b8f6da5f347f48515215ceee4ae37", |
| "lessThan": "f28bba37fe244889b81bb5c508d3f6e5c6e342c5", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "2afc9166f79b8f6da5f347f48515215ceee4ae37", |
| "lessThan": "57baab0f376bec8f54b0fe6beb8f77a57c228063", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "2afc9166f79b8f6da5f347f48515215ceee4ae37", |
| "lessThan": "84bd4c2ae9c3d0a7d3a5c032ea7efff17af17e17", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "2afc9166f79b8f6da5f347f48515215ceee4ae37", |
| "lessThan": "43f00210cb257bcb0387e8caeb4b46375d67f30c", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "2afc9166f79b8f6da5f347f48515215ceee4ae37", |
| "lessThan": "5d43e072285e81b0b63cee7189b3357c7768a43b", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "2afc9166f79b8f6da5f347f48515215ceee4ae37", |
| "lessThan": "ac107356aabc362aaeb77463e814fc067a5d3957", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "2afc9166f79b8f6da5f347f48515215ceee4ae37", |
| "lessThan": "a4c99b57d43bab45225ba92d574a8683f9edc8e4", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "2afc9166f79b8f6da5f347f48515215ceee4ae37", |
| "lessThan": "a90bca2228c0646fc29a72689d308e5fe03e6d78", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "e8a37b2fd5b5087bec6cbbf6946ee3caa712953b", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "a6abc93760dd07fcd29760b70e6e7520f22cb288", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "461a6385e58e8247e6ba2005aa5d1b8d980ee4a2", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "8a5e02a0f46ea33ed19e48e096a8e8d28e73d10a", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "c984f4d1d40a2f349503b3faf946502ccbf02f9f", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "807d1d299a04e9ad9a9dac55419c1137a105254b", |
| "status": "affected", |
| "versionType": "git" |
| } |
| ] |
| }, |
| { |
| "product": "Linux", |
| "vendor": "Linux", |
| "defaultStatus": "affected", |
| "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", |
| "programFiles": [ |
| "fs/sysfs/file.c" |
| ], |
| "versions": [ |
| { |
| "version": "4.19", |
| "status": "affected" |
| }, |
| { |
| "version": "0", |
| "lessThan": "4.19", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "4.19.313", |
| "lessThanOrEqual": "4.19.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.4.275", |
| "lessThanOrEqual": "5.4.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.10.216", |
| "lessThanOrEqual": "5.10.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.15.157", |
| "lessThanOrEqual": "5.15.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.1.88", |
| "lessThanOrEqual": "6.1.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.6.29", |
| "lessThanOrEqual": "6.6.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.8.8", |
| "lessThanOrEqual": "6.8.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.9", |
| "lessThanOrEqual": "*", |
| "status": "unaffected", |
| "versionType": "original_commit_for_fix" |
| } |
| ] |
| } |
| ], |
| "cpeApplicability": [ |
| { |
| "nodes": [ |
| { |
| "operator": "OR", |
| "negate": false, |
| "cpeMatch": [ |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.19", |
| "versionEndExcluding": "4.19.313" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.19", |
| "versionEndExcluding": "5.4.275" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.19", |
| "versionEndExcluding": "5.10.216" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.19", |
| "versionEndExcluding": "5.15.157" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.19", |
| "versionEndExcluding": "6.1.88" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.19", |
| "versionEndExcluding": "6.6.29" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.19", |
| "versionEndExcluding": "6.8.8" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.19", |
| "versionEndExcluding": "6.9" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "3.16.62" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "3.18.121" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.4.154" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.9.125" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.14.68" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.18.6" |
| } |
| ] |
| } |
| ] |
| } |
| ], |
| "references": [ |
| { |
| "url": "https://git.kernel.org/stable/c/f28bba37fe244889b81bb5c508d3f6e5c6e342c5" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/57baab0f376bec8f54b0fe6beb8f77a57c228063" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/84bd4c2ae9c3d0a7d3a5c032ea7efff17af17e17" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/43f00210cb257bcb0387e8caeb4b46375d67f30c" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/5d43e072285e81b0b63cee7189b3357c7768a43b" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/ac107356aabc362aaeb77463e814fc067a5d3957" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/a4c99b57d43bab45225ba92d574a8683f9edc8e4" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/a90bca2228c0646fc29a72689d308e5fe03e6d78" |
| } |
| ], |
| "title": "fs: sysfs: Fix reference leak in sysfs_break_active_protection()", |
| "x_generator": { |
| "engine": "bippy-1.2.0" |
| } |
| } |
| }, |
| "cveMetadata": { |
| "assignerOrgId": "f4215fc3-5b6b-47ff-a258-f7189bd81038", |
| "cveID": "CVE-2024-26993", |
| "requesterUserId": "gregkh@kernel.org", |
| "serial": "1", |
| "state": "PUBLISHED" |
| }, |
| "dataType": "CVE_RECORD", |
| "dataVersion": "5.0" |
| } |