CVE-2024-35939: dma-direct: Leak pages on dma_set_decrypted() failure
dma-direct: Leak pages on dmasetdecrypted() failure
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.133-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.86 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.27 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8.6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35939?
CVE-2024-35939 is categorized as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2024-35939?
To resolve CVE-2024-35939, update your Linux kernel to version 6.1.86, 6.6.27, 6.8.6, or 6.9, or use the corresponding patched versions in Debian.
What systems are affected by CVE-2024-35939?
CVE-2024-35939 affects Linux kernel versions prior to 6.1.86, 6.6.27, 6.8.6, 6.9, and Debian versions up to 5.10.226-1.
What types of attacks can exploit CVE-2024-35939?
CVE-2024-35939 can potentially be exploited by an untrusted host, leading to memory management issues.
Is CVE-2024-35939 related to memory management in Linux?
Yes, CVE-2024-35939 involves a memory management flaw linked to the dma_set_decrypted function in the Linux kernel.