---
cve: "CVE-2024-26894"
severity: "MEDIUM"
cvss: 6.0
epss: "25%"
vendor: "Linux"
kev: false
exploited: false
published: "2024-04-17 11:15:10"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-08-31T12:50:47+02:00"
---

# CVE-2024-26894

> 6.0 MEDIUM

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()

After unregistering the CPU idle device, the memory associated with
it is not freed, leading to a memory leak:

unreferenced object 0xffff896282f6c000 (size 1024):
  comm "swapper/0", pid 1, jiffies 4294893170
  hex dump (first 32 bytes):
    00 00 00 00 0b 00 00 00 00 00 00 00 00 00 00 00  ................
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
  backtrace (crc 8836a742):
    [] kmalloc_trace+0x29d/0x340
    [] acpi_processor_power_init+0xf3/0x1c0
    [] __acpi_processor_start+0xd3/0xf0
    [] acpi_processor_start+0x2c/0x50
    [] really_probe+0xe2/0x480
    [] __driver_probe_device+0x78/0x160
    [] driver_probe_device+0x1f/0x90
    [] __driver_attach+0xce/0x1c0
    [] bus_for_each_dev+0x70/0xc0
    [] bus_add_driver+0x112/0x210
    [] driver_register+0x55/0x100
    [] acpi_processor_driver_init+0x3b/0xc0
    [] do_one_initcall+0x41/0x300
    [] kernel_init_freeable+0x320/0x470
    [] kernel_init+0x16/0x1b0
    [] ret_from_fork+0x2d/0x50

Fix this by freeing the CPU idle device after unregistering it.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 4.19.311
- Kernel ≥ 5.4.273
- Kernel ≥ 5.10.214
- Kernel ≥ 5.15.153
- Kernel ≥ 6.1.83
- Kernel ≥ 6.6.23
- Kernel ≥ 6.7.11
- Kernel ≥ 6.8.2

## Referenzen

- <https://git.kernel.org/stable/c/d351bcadab6caa6d8ce7159ff4b77e2da35c09fa>
- <https://git.kernel.org/stable/c/ea96bf3f80625cddba1391a87613356b1b45716d>
- <https://git.kernel.org/stable/c/c2a30c81bf3cb9033fa9f5305baf7c377075e2e5>
- <https://git.kernel.org/stable/c/1cbaf4c793b0808532f4e7b40bc4be7cec2c78f2>
- <https://git.kernel.org/stable/c/fad9bcd4d754cc689c19dc04d2c44b82c1a5d6c8>
- <https://git.kernel.org/stable/c/3d48e5be107429ff5d824e7f2a00d1b610d36fbc>
- <https://git.kernel.org/stable/c/8d14a4d0afb49a5b8535d414c782bb334860e73e>
- <https://git.kernel.org/stable/c/cd5c2d0b09d5b6d3f0a7bbabe6761a4997e9dee9>
- <https://git.kernel.org/stable/c/e18afcb7b2a12b635ac10081f943fcf84ddacc51>
- <https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html>
- <https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html>
- <https://cert-portal.siemens.com/productcert/html/ssa-265688.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-26894) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
