CVE-2024-35928 Affecting kernel-modules package, versions *
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL8-KERNELMODULES-6920525
- published 20 May 2024
- disclosed 19 May 2024
Introduced: 19 May 2024
CVE-2024-35928 Open this link in a new tabHow to fix?
There is no fixed version for RHEL:8
kernel-modules
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream kernel-modules
package and not the kernel-modules
package as distributed by RHEL
.
See How to fix?
for RHEL:8
relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/amdgpu: Fix potential ioremap() memory leaks in amdgpu_device_init()
This ensures that the memory mapped by ioremap for adev->rmmio, is properly handled in amdgpu_device_init(). If the function exits early due to an error, the memory is unmapped. If the function completes successfully, the memory remains mapped.
Reported by smatch: drivers/gpu/drm/amd/amdgpu/amdgpu_device.c:4337 amdgpu_device_init() warn: 'adev->rmmio' from ioremap() not released on lines: 4035,4045,4051,4058,4068,4337
References
- https://access.redhat.com/security/cve/CVE-2024-35928
- https://git.kernel.org/stable/c/14ac934db851642ea8cd1bd4121c788a8899ef69
- https://git.kernel.org/stable/c/aa665c3a2aca2ffe31b9645bda278e96dfc3b55c
- https://git.kernel.org/stable/c/c5f9fe2c1e5023fa096189a8bfba6420aa035587
- https://git.kernel.org/stable/c/eb4f139888f636614dab3bcce97ff61cefc4b3a7