In the Linux kernel, the following vulnerability has been resolved:
net: sched: fix memory leak in tcindex_partial_destroy_work
Syzbot reported memory leak in tcindex_set_parms(). The problem was in non-freed perfect hash in tcindex_partial_destroy_work().
In tcindex_set_parms() new tcindex_data is allocated and some fields from old one are copied to new one, but not the perfect hash. Since tcindex_partial_destroy_work() is the destroy function for old tcindex_data, we need to free perfect hash to avoid memory leak.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-headersUpgrade kernelUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfoUpgrade bpftoolUpgrade python-perf-debuginfoUpgrade kernel-tools-develUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-develUpgrade perfUpgrade python-perfUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-toolsUpgrade perf-debuginfoUpgrade kernel-livepatch-5.10.59-52.142Upgrade bpftool-debuginfo | Mar 14, 2025 | May 21, 2024 |
| Debian | — | Upgrade linux | Jul 30, 2024 | May 21, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 21, 2024 |
| Ubuntu | — | Upgrade linux-fipsUpgrade linux-oracleUpgrade linux-azureUpgrade linux-gcpUpgrade linux-raspi-5.4Upgrade linux-raspiUpgrade linux-awsUpgrade linux-kvmUpgrade linux-bluefieldUpgrade linux-azure-5.4Upgrade linux-oracle-5.4Upgrade linux-gkeopUpgrade linuxUpgrade linux-gcp-5.4Upgrade linux-aws-5.4Upgrade linux-hwe-5.4Upgrade linux-aws-fipsUpgrade linux-gcp-fipsUpgrade linux-azure-fipsUpgrade linux-ibm | Nov 19, 2024 | May 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub