Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2024-0443

CVE-2024-0443: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium5.5

    Medium [CVE-2024-0443] blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.

    CVE-2024-0443Source published Source updated

    A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error. This flaw affects RHEL 8.6 and above, and RHEL9.2 and above. Released kernel streamers only. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-402. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.2…

    Affected products in this advisory
    • Red Hat Enterprise Linux 8
    • Red Hat Enterprise Linux 9.2 Extended Update Support
    • Red Hat package: kernel-rt
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • kernel-0:4.18.0-513.5.1.el8_9
    • kernel-0:5.14.0-284.40.1.el9_2
    • RHSA-2023:7077
    • RHSA-2023:7370
    Mitigation guidance
    • This flaw can be mitigated with the possible workaround identified below: - systemd.unified_cgroup_hierarchy=1 or - cgroup_disable=blkio

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery