In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: fix zcard and zqueue hot-unplug memleak
Tests with kvm and a kmemdebug kernel showed, that on hot unplug the zcard and zqueue structs for the unplugged card or queue are not properly freed because of a mismatch with get/put for the embedded kref counter.
This fix now adjusts the handling of the kref counters. With init the kref counter starts with 1. This initial value needs to drop to zero with the unregister of the card or queue to trigger the release and free the object.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Feb 27, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 27, 2024 |
| Suse | — | Upgrade kernel-default-baseUpgrade kernel-macrosUpgrade reiserfs-kmp-defaultUpgrade kernel-64kb-develUpgrade kernel-defaultUpgrade kernel-symsUpgrade kernel-docsUpgrade kernel-64kbUpgrade kernel-default-develUpgrade kernel-preempt-develUpgrade kernel-develUpgrade kernel-obs-buildUpgrade kernel-zfcpdumpUpgrade kernel-preemptUpgrade kernel-source | Aug 9, 2024 | Feb 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub