Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +3 more
A memory leak vulnerability has been identified in the Linux kernel's s390/zcrypt component. When the function dev_set_name() fails, the zcdn_create() function does not release the newly allocated resources, leading to a memory leak. This issue affects several versions of the Linux kernel.
The vulnerability can lead to a memory leak, causing increased memory usage and potentially leading to exhaustion of system resources.
The vulnerability can be reproduced by creating a zcrypt device node and simulating a failure in the dev_set_name() function. This will cause the zcdn_create() function to exit without freeing the allocated resources, leading to a memory leak.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.