In the Linux kernel, the following vulnerability has been resolved:
net: sched: fix memory leak in tcindex_partial_destroy_work
Syzbot reported memory leak in tcindex_set_parms(). The problem was in non-freed perfect hash in tcindex_partial_destroy_work().
In tcindex_set_parms() new tcindex_data is allocated and some fields from old one are copied to new one, but not the perfect hash. Since tcindex_partial_destroy_work() is the destroy function for old tcindex_data, we need to free perfect hash to avoid memory leak.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade perfUpgrade kernel-debuginfo-common-aarch64Upgrade python-perfUpgrade bpftool-debuginfoUpgrade kernel-toolsUpgrade perf-debuginfoUpgrade kernel-livepatch-5.10.59-52.142Upgrade kernel-headersUpgrade kernel-debuginfoUpgrade kernel-tools-develUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernelUpgrade python-perf-debuginfoUpgrade kernel-develUpgrade bpftool | Mar 14, 2025 | May 21, 2024 |
| Debian | — | Upgrade linux | Jul 30, 2024 | May 21, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 21, 2024 |
| Ubuntu | — | Upgrade linux-oracle-5.4Upgrade linux-azure-5.4Upgrade linux-awsUpgrade linux-kvmUpgrade linux-gcpUpgrade linux-bluefieldUpgrade linux-oracleUpgrade linux-raspiUpgrade linux-raspi-5.4Upgrade linux-fipsUpgrade linux-azureUpgrade linuxUpgrade linux-gkeopUpgrade linux-aws-5.4Upgrade linux-aws-fipsUpgrade linux-gcp-fipsUpgrade linux-gcp-5.4Upgrade linux-azure-fipsUpgrade linux-hwe-5.4Upgrade linux-ibm | Nov 19, 2024 | May 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub