|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2024-35926: kernel: crypto: iaa - Fix async_disable descriptor leak | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | SMASH SMASH <smash_bz> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | IN_PROGRESS --- | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | gianluca.gabrielli, jlee |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/406616/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2024-35926:4.4:(AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
SMASH SMASH
2024-05-20 16:04:08 UTC
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-35926
262534ddc88d ("crypto: iaa - Fix async_disable descriptor leak") merged v6.9-rc1~89^2~8
No Fixes tag. Requires manual review for affected branches.
Security fix for CVE-2024-35926 bsc#1224655 with CVSS 4.4
Experts candidates: oneukum@suse.de duwe@suse.de
..............................
ACTION NEEDED!
SLE12-SP5: MANUAL: might need backport of 262534ddc88dfea7474ed18adfecf856e4fbe054 ()
SLE15-SP6: MANUAL: might need backport of 262534ddc88dfea7474ed18adfecf856e4fbe054 ()
SLE12-SP3-TD: MANUAL: might need backport of 262534ddc88dfea7474ed18adfecf856e4fbe054 ()
SLE15-SP5: MANUAL: might need backport of 262534ddc88dfea7474ed18adfecf856e4fbe054 ()
Hi Oliver, Because this is a issue for crypto. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot! (In reply to Joey Lee from comment #2) > joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> > ./scripts/check-kernel-fix CVE-2024-35926 > 262534ddc88d ("crypto: iaa - Fix async_disable descriptor leak") merged > v6.9-rc1~89^2~8 > No Fixes tag. Requires manual review for affected branches. > Security fix for CVE-2024-35926 bsc#1224655 with CVSS 4.4 > Experts candidates: oneukum@suse.de duwe@suse.de > .............................. > ACTION NEEDED! > SLE15-SP6: MANUAL: might need backport of > 262534ddc88dfea7474ed18adfecf856e4fbe054 () The driver was added in v6.8 and has been backported only to SLE15-SP6 No other kernel is affected Fix submitted to SLE15-SP6 |