CVE-2024-43861: net: usb: qmi_wwan: fix memory leak for not ip packets
Published Aug 20, 2024
·Updated
In the Linux kernel, the following vulnerability has been resolved:
net: usb: qmiwwan: fix memory leak for not ip packets
Free the unused skb when not ip packets arrive.
Affected Software
11 affected componentsFixes available
Linux Linux kernel>=4.12<4.19.320
Linux Linux kernel>=4.20<5.4.282
Linux Linux kernel>=5.5<5.10.224
Linux Linux kernel>=5.11<5.15.165
Linux Linux kernel>=5.16<6.1.105
Linux Linux kernel>=6.2<6.6.46
Linux Linux kernel>=6.7<6.10.5
Linux Linux kernel=6.11-rc1
Linux Linux kernel=6.11-rc2
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Remediation
Event History
Aug 20, 2024
CVE Published
via MITRE·09:37 PM
Data Sourced
via MITRE·09:37 PM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 27, 2025
Data Sourced
via Ubuntu·12:34 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43861?
CVE-2024-43861 is considered a moderate severity vulnerability due to potential memory leaks in the Linux kernel.
2
How do I fix CVE-2024-43861?
To fix CVE-2024-43861, update your Linux kernel to a version that addresses the memory leak issue.
3
Which Linux kernel versions are affected by CVE-2024-43861?
CVE-2024-43861 affects multiple Linux kernel versions from 4.12 to 6.11-rc2.
4
What type of vulnerability is CVE-2024-43861?
CVE-2024-43861 is a memory leak vulnerability associated with the qmi_wwan driver in the Linux kernel.
5
Is there a recommended kernel version to mitigate CVE-2024-43861?
Yes, upgrading to kernel version 6.1.123-1 or later is recommended to mitigate CVE-2024-43861.