In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Fix some memory leaks in an error handling path of 'log_replay()'
All error handling paths lead to 'out' where many resources are freed.
Do it as well here instead of a direct return, otherwise 'log', 'ra' and 'log->one_page_buf' (at least) will leak.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-toolsUpgrade kernel-tools-debuginfoUpgrade kernelUpgrade bpftoolUpgrade kernel-develUpgrade kernel-livepatch-5.15.50-23.125Upgrade bpftool-debuginfoUpgrade python-perfUpgrade kernel-debuginfo-common-x86_64Upgrade perfUpgrade kernel-tools-develUpgrade kernel-debuginfo-common-aarch64Upgrade perf-debuginfoUpgrade kernel-headersUpgrade python-perf-debuginfoUpgrade kernel-debuginfo | May 22, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-riscv-5.15Upgrade linux-gkeUpgrade linuxUpgrade linux-gcpUpgrade linux-intel-iotgUpgrade linux-gkeopUpgrade linux-azure-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-realtimeUpgrade linux-nvidiaUpgrade linux-awsUpgrade linux-raspiUpgrade linux-gcp-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-oracle-5.15Upgrade linux-aws-5.15Upgrade linux-hwe-5.15Upgrade linux-azureUpgrade linux-oracleUpgrade linux-kvmUpgrade linux-ibmUpgrade linux-lowlatency | Mar 19, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub