CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-56742: vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages()

Description

In the Linux kernel, the following vulnerability has been resolved:

vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages()

Fix an unwind issue in mlx5vf_add_migration_pages().

If a set of pages is allocated but fails to be added to the SG table,
they need to be freed to prevent a memory leak.

Any pages successfully added to the SG table will be freed as part of
mlx5vf_free_data_buffer().

Classification

CVE ID: CVE-2024-56742

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 5.08% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://git.kernel.org/stable/c/769fe4ce444b646b0bf6ac308de80686c730c7df
https://git.kernel.org/stable/c/c44f1b2ddfa81c8d7f8e9b6bc76c427bc00e69d5
https://git.kernel.org/stable/c/22e87bf3f77c18f5982c19ffe2732ef0c7a25f16

Timeline