SB2024061075 - Memory leak in Linux kernel octeontx2 nic driver
Published: June 10, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2024-35975)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the otx2_qos_read_txschq_cfg_tl() function in drivers/net/ethernet/marvell/octeontx2/nic/qos.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/7af5582ea67209a23e44be9a9612ba7897be1f47
- https://git.kernel.org/stable/c/b34fe77a1b18654233e4e54b334fcaeddf487100
- https://git.kernel.org/stable/c/bccb798e07f8bb8b91212fe8ed1e421685449076
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.28
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8.7