CVE-2024-27073: media: ttpci: fix two memleaks in budget_av_attach
In the Linux kernel, the following vulnerability has been resolved:
media: ttpci: fix two memleaks in budgetavattach
When saa7146registerdevice and saa7146vvinit fails, budgetavattach should free the resources it allocates, like the error-handling of ttpcibudgetinit does. Besides, there are two fixme comment refers to such deallocations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27073?
CVE-2024-27073 has a medium severity rating due to its potential impact on resource management within the Linux kernel.
How do I fix CVE-2024-27073?
To fix CVE-2024-27073, upgrade to the patched versions of the Linux package: 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.10-1, or 6.12.11-1.
What systems are affected by CVE-2024-27073?
CVE-2024-27073 affects Debian installations using the Linux kernel versions specified in the fixed versions.
What kind of vulnerability is CVE-2024-27073?
CVE-2024-27073 is a memory management vulnerability that can lead to resource leaks if not addressed.
Is there a workaround for CVE-2024-27073?
There is no official workaround for CVE-2024-27073; updating to the secure versions is the recommended approach.