SB2024123030 - Memory leak in Linux kernel xen xenbus driver
Published: December 30, 2024 Updated: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2024-53198)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the xenbus_dev_probe() function in drivers/xen/xenbus/xenbus_probe.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0aa9e30b5b4af5dd504801689d6d84c584290a45
- https://git.kernel.org/stable/c/217bdce88b104269b73603b84d0ab4dd04f481bc
- https://git.kernel.org/stable/c/2f977a4c82d35d063f5fe198bbc501c4b1c5ea0e
- https://git.kernel.org/stable/c/3fc0996d2fefe61219375fd650601724b8cf2d30
- https://git.kernel.org/stable/c/804b96f8d0a02fa10b92f28b2e042f9128ed3ffc
- https://git.kernel.org/stable/c/87106169b4ce26f85561f953d13d1fd86d99b612
- https://git.kernel.org/stable/c/afc545da381ba0c651b2658966ac737032676f01
- https://git.kernel.org/stable/c/e8823e6ff313465910edea07581627d85e68d9fd
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.174