Bug 1227870 (CVE-2024-41002) - VUL-0: CVE-2024-41002: kernel: crypto: hisilicon/sec - fix memory leak for sec resource release
Summary: VUL-0: CVE-2024-41002: kernel: crypto: hisilicon/sec - fix memory leak for se...
Status: NEW
Alias: CVE-2024-41002
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Kernel Bugs
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/413929/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-41002:4.4:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-15 19:41 UTC by SMASH SMASH
Modified: 2024-07-15 20:15 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-07-15 19:41:11 UTC
In the Linux kernel, the following vulnerability has been resolved:

crypto: hisilicon/sec - Fix memory leak for sec resource release

The AIV is one of the SEC resources. When releasing resources,
it need to release the AIV resources at the same time.
Otherwise, memory leakage occurs.

The aiv resource release is added to the sec resource release
function.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-41002
https://www.cve.org/CVERecord?id=CVE-2024-41002
https://git.kernel.org/stable/c/36810d2db3496bb8b4db7ccda666674a5efc7b47
https://git.kernel.org/stable/c/7c42ce556ff65995c8875c9ed64141c14238e7e6
https://git.kernel.org/stable/c/9f21886370db451b0fdc651f6e41550a1da70601
https://git.kernel.org/stable/c/a886bcb0f67d1e3d6b2da25b3519de59098200c2
https://git.kernel.org/stable/c/bba4250757b4ae1680fea435a358d8093f254094
https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-41002.mbox