CVE-2024-47677
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: exfat: resolve memory leak from exfat_create_upcase_table() If exfat_load_upcase_table reaches end and returns -EINVAL, allocated memory doesn't get freed and while exfat_load_default_upcase_table allocates more memory, leading to a memory leak. Here's link to syzkaller crash report illustrating this issue: https://syzkaller.appspot.com/text?tag=CrashReport&x=1406c201980000
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.02%• Percentile: 5%
Techniques & Countermeasures
- CWE-401•Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Affected Systems
- linux•linux
≥ a13d1a4de3b0fe3c41d818697d691c886c5585fa, < f9835aec49670c46ebe2973032caaa1043b3d4da | ≥ a13d1a4de3b0fe3c41d818697d691c886c5585fa, < 331ed2c739ce656a67865f6b3ee0a478349d78cb | ≥ a13d1a4de3b0fe3c41d818697d691c886c5585fa, < c290fe508eee36df1640c3cb35dc8f89e073c8a8 | 6.8
- linux•linux_kernel
≥ 6.8, < 6.10.13 | ≥ 6.11, < 6.11.2