CVE-2024-35859

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-35859
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35859.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-35859
Downstream
Published
2024-05-17T14:47:34Z
Modified
2025-10-17T03:42:22.319840Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
block: fix module reference leakage from bdev_open_by_dev error path
Details

In the Linux kernel, the following vulnerability has been resolved:

block: fix module reference leakage from bdevopenby_dev error path

At the time bdevmayopen() is called, module reference is grabbed already, hence module reference should be released if bdevmayopen() failed.

This problem is found by code review.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ed5cc702d311c14b653323d76062b0294effa66e
Fixed
0e9327c67410b129bf85e5c3a5aaea518328636f
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ed5cc702d311c14b653323d76062b0294effa66e
Fixed
9617cd6f24b294552a817f80f5225431ef67b540

Affected versions

v6.*

v6.7
v6.7-rc2
v6.7-rc3
v6.7-rc4
v6.7-rc5
v6.7-rc6
v6.7-rc7
v6.7-rc8
v6.8
v6.8-rc1
v6.8-rc2
v6.8-rc3
v6.8-rc4
v6.8-rc5
v6.8-rc6
v6.8-rc7
v6.8.1
v6.8.2
v6.8.3
v6.8.4
v6.8.5
v6.8.6
v6.8.7
v6.8.8
v6.9-rc1
v6.9-rc2
v6.9-rc3

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.8.9