CVE-2024-39493
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-39493 is a memory leak vulnerability discovered in the Linux kernel's crypto QAT (Quick Assist Technology) driver. The vulnerability was identified in the ADFDEVRESETSYNC functionality, where using completiondone to determine whether the caller has gone away only works after a complete call. Additionally, there was a potential Use-After-Free (UAF) vulnerability when the caller has not yet called waitforcompletion (NVD).

Technical details

The vulnerability exists in the Linux kernel's crypto QAT driver, specifically in the ADFDEVRESET_SYNC mechanism. The issue stems from improper memory management during device reset operations. The CVSS v3.1 base score is 5.5 (Medium), with vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The vulnerability affects multiple Linux kernel versions including 4.19.312 through 4.19.316, 5.4.274 through 5.4.278, 5.10.215 through 5.10.219, 5.15.154 through 5.15.161, and others (NVD).

Impact

The vulnerability could lead to memory leaks and potential Use-After-Free conditions in the Linux kernel's crypto QAT driver. This could affect system stability and potentially lead to denial of service conditions (NVD).

Mitigation and workarounds

The vulnerability has been fixed by modifying the code to use cancelworksync and then safely freeing the memory. The fix has been implemented in various Linux kernel versions and distributions. Ubuntu has released patches for affected versions including 24.04 LTS, 22.04 LTS, and 20.04 LTS (Ubuntu). Debian has also fixed the issue in bullseye (5.10.234-1) and bookworm (6.1.128-1) releases (Debian).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40258HIGH7
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-devel-matched
NoNoDec 04, 2025
CVE-2025-40259MEDIUM6.2
  • Linux KernelLinux Kernel
  • kernel-rt-64k
NoNoDec 04, 2025
CVE-2025-40264MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-modules-extra
NoNoDec 04, 2025
CVE-2025-40254MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-devel-matched
NoNoDec 04, 2025
CVE-2025-40253MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-partner
NoNoDec 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management