In the Linux kernel, the following vulnerability has been resolved:
iommu/arm-smmu: Fix arm_smmu_device refcount leak in address translation
The reference counting issue happens in several exception handling paths of arm_smmu_iova_to_phys_hard(). When those error scenarios occur, the function forgets to decrease the refcount of "smmu" increased by arm_smmu_rpm_get(), causing a refcount leak.
Fix this issue by jumping to "out" label when those error scenarios occur.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade perf-debuginfoUpgrade perfUpgrade kernel-debuginfo-common-aarch64Upgrade python-perfUpgrade kernel-toolsUpgrade bpftoolUpgrade bpftool-debuginfoUpgrade kernel-livepatch-5.10.59-52.142Upgrade kernel-develUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-tools-develUpgrade kernelUpgrade kernel-debuginfoUpgrade kernel-headersUpgrade python-perf-debuginfoUpgrade kernel-tools-debuginfo | Jun 26, 2024 | May 21, 2024 |
| Debian | — | Upgrade linux | Jul 30, 2024 | May 21, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 21, 2024 |
| Ubuntu | — | Upgrade linux-awsUpgrade linux-gkeopUpgrade linux-oracle-5.4Upgrade linux-azure-fipsUpgrade linux-azure-fde-5.15Upgrade linux-hwe-5.4Upgrade linux-gcp-fipsUpgrade linux-gcp-5.4Upgrade linuxUpgrade linux-gcpUpgrade linux-raspi-5.4Upgrade linux-ibmUpgrade linux-oracleUpgrade linux-kvmUpgrade linux-aws-5.4Upgrade linux-azure-5.4Upgrade linux-aws-fipsUpgrade linux-fipsUpgrade linux-raspiUpgrade linux-azureUpgrade linux-bluefield | Nov 19, 2024 | May 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub