• 公告ID (KylinSec-SA-2024-4516)

摘要:

In the Linux kernel, the following vulnerability has been resolved:

net/9p/usbg: fix handling of the failed kzalloc() memory allocation

On the linux-next, next-20241108 vanilla kernel, the coccinelle tool gave the
following error report:

./net/9p/trans_usbg.c:912:5-11: ERROR: allocation function on line 911 returns
NULL not ERR_PTR on failure

kzalloc() failure is fixed to handle the NULL return case on the memory exhaustion.

安全等级: Low

公告ID: KylinSec-SA-2024-4516

发布日期: 2025年1月4日

关联CVE: CVE-2024-56730  

  • 详细介绍

1. 漏洞描述

   

In the Linux kernel, the following vulnerability has been resolved:

net/9p/usbg: fix handling of the failed kzalloc() memory allocation

On the linux-next, next-20241108 vanilla kernel, the coccinelle tool gave the
following error report:

./net/9p/trans_usbg.c:912:5-11: ERROR: allocation function on line 911 returns
NULL not ERR_PTR on failure

kzalloc() failure is fixed to handle the NULL return case on the memory exhaustion.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2024-56730 KY3.4-5 kernel Unaffected
CVE-2024-56730 KY3.5.3 kernel Unaffected
CVE-2024-56730 V6 kernel Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-4515 下一篇:KylinSec-SA-2024-4517