CVE-2024-39493 - CVE House
Back to Database
Status published Unknown CVE-2024-39493

crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak Using completion_done to determine whether the caller has gone away only works after a complete call. Furthermore it's still possible that the caller has not yet called wait_for_completion, resulting in another potential UAF. Fix this by making the caller use cancel_work_sync and then freeing the memory safely.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-39493

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
daba62d9eeddcc5b1081be7d348ca836c83c59d7, 8e81cd58aee14a470891733181a47d123193ba81, d03092550f526a79cf1ade7f0dfa74906f39eb71, 4ae5a97781ce7d6ecc9c7055396535815b64ca4f, 226fc408c5fcd23cc4186f05ea3a09a7a9aef2f7, 8a5a7611ccc7b1fba8d933a9f22a2e76859d94dc, 7d42e097607c4d246d99225bf2b195b6167a210c, 0c2cf5142bfb634c0ef0a1a69cdf37950747d0be, bb279ead42263e9fb09480f02a4247b2c287d828, 4.19.312, 5.4.274, 5.10.215, 5.15.154, 6.1.84, 6.6.24, 6.7.12, 6.8.3, 6.9, 0, 4.19.316, 5.4.278, 5.10.219, 5.15.161, 6.1.94, 6.6.34, 6.9.5, 6.10

Timeline

Official Publish: July 10th, 2024
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.