CVE-2024-39493

Source
https://cve.org/CVERecord?id=CVE-2024-39493
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-39493.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-39493
Downstream
Related
Published
2024-07-10T07:18:39.443Z
Modified
2026-03-13T07:57:00.946322Z
Summary
crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: qat - Fix ADFDEVRESET_SYNC memory leak

Using completiondone to determine whether the caller has gone away only works after a complete call. Furthermore it's still possible that the caller has not yet called waitfor_completion, resulting in another potential UAF.

Fix this by making the caller use cancelworksync and then freeing the memory safely.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39493.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
daba62d9eeddcc5b1081be7d348ca836c83c59d7
Fixed
0ce5964b82f212f4df6a9813f09a0b5de15bd9c8
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8e81cd58aee14a470891733181a47d123193ba81
Fixed
6396b33e98c096bff9c253ed49c008247963492a
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d03092550f526a79cf1ade7f0dfa74906f39eb71
Fixed
a718b6d2a329e069b27d9049a71be5931e71d960
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4ae5a97781ce7d6ecc9c7055396535815b64ca4f
Fixed
3fb4601e0db10d4fe25e46f3fa308d40d37366bd
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
226fc408c5fcd23cc4186f05ea3a09a7a9aef2f7
Fixed
e7428e7e3fe94a5089dc12ffe5bc31574d2315ad
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8a5a7611ccc7b1fba8d933a9f22a2e76859d94dc
Fixed
c2d443aa1ae3175c13a665f3a24b8acd759ce9c3
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7d42e097607c4d246d99225bf2b195b6167a210c
Fixed
d0fd124972724cce0d48b9865ce3e273ef69e246
Fixed
d3b17c6d9dddc2db3670bc9be628b122416a3d26
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
0c2cf5142bfb634c0ef0a1a69cdf37950747d0be
Last affected
bb279ead42263e9fb09480f02a4247b2c287d828

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-39493.json"