In the Linux kernel, the following vulnerability has been resolved:
net: thunderbolt: fix memory leak in tbnet_open()
When tb_ring_alloc_rx() failed in tbnet_open(), ida that allocated in tb_xdomain_alloc_out_hopid() is not released. Add tb_xdomain_release_out_hopid() to the error path to release ida.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Oct 23, 2024 | Oct 23, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 21, 2024 |
| Ubuntu | — | Upgrade linux-raspiUpgrade linux-gcpUpgrade linux-oracle-5.15Upgrade linux-intel-iot-realtimeUpgrade linux-bluefieldUpgrade linux-lowlatencyUpgrade linux-aws-5.15Upgrade linuxUpgrade linux-riscv-5.15Upgrade linux-intel-iotgUpgrade linux-lowlatency-hwe-5.15Upgrade linux-gkeUpgrade linux-ibmUpgrade linux-gkeopUpgrade linux-nvidiaUpgrade linux-realtimeUpgrade linux-azure-5.15Upgrade linux-kvmUpgrade linux-intel-iotg-5.15Upgrade linux-oracleUpgrade linux-azure-fdeUpgrade linux-azureUpgrade linux-awsUpgrade linux-gcp-5.15Upgrade linux-azure-fde-5.15Upgrade linux-gkeop-5.15Upgrade linux-hwe-5.15 | Nov 19, 2024 | Oct 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub