CVE-2024-40997: cpufreq: amd-pstate: fix memory leak on CPU EPP exit
cpufreq: amd-pstate: fix memory leak on CPU EPP exit
Other sources
Linux Kernel is vulnerable to a denial of service, caused by a memory leak on CPU EPP Exit. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40997?
CVE-2024-40997 is classified as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2024-40997?
To fix CVE-2024-40997, update the kernel to versions 6.6.36, 6.9.7, or 6.10 for Red Hat systems, or apply the appropriate patch for Debian systems.
What is the impact of CVE-2024-40997?
The impact of CVE-2024-40997 includes a potential memory leak during CPU EPP exit in the Linux kernel which may lead to resource depletion.
Which versions of the Linux kernel are affected by CVE-2024-40997?
CVE-2024-40997 affects Linux kernel versions prior to 6.6.36, between 6.7 and 6.9.7, and versions prior to 6.10.
Is there a public reference for CVE-2024-40997?
Yes, details about CVE-2024-40997 can be found in the Linux kernel's changelog and related commits.