{"id":"DEBIAN-CVE-2024-56534","details":"In the Linux kernel, the following vulnerability has been resolved:  isofs: avoid memory leak in iocharset  A memleak was found as below:  unreferenced object 0xffff0000d10164d8 (size 8):   comm \"pool-udisksd\", pid 108217, jiffies 4295408555   hex dump (first 8 bytes):     75 74 66 38 00 cc cc cc                          utf8....   backtrace (crc de430d31):     [\u003cffff800081046e6c\u003e] kmemleak_alloc+0xb8/0xc8     [\u003cffff8000803e6c3c\u003e] __kmalloc_node_track_caller_noprof+0x380/0x474     [\u003cffff800080363b74\u003e] kstrdup+0x70/0xfc     [\u003cffff80007bb3c6a4\u003e] isofs_parse_param+0x228/0x2c0 [isofs]     [\u003cffff8000804d7f68\u003e] vfs_parse_fs_param+0xf4/0x164     [\u003cffff8000804d8064\u003e] vfs_parse_fs_string+0x8c/0xd4     [\u003cffff8000804d815c\u003e] vfs_parse_monolithic_sep+0xb0/0xfc     [\u003cffff8000804d81d8\u003e] generic_parse_monolithic+0x30/0x3c     [\u003cffff8000804d8bfc\u003e] parse_monolithic_mount_data+0x40/0x4c     [\u003cffff8000804b6a64\u003e] path_mount+0x6c4/0x9ec     [\u003cffff8000804b6e38\u003e] do_mount+0xac/0xc4     [\u003cffff8000804b7494\u003e] __arm64_sys_mount+0x16c/0x2b0     [\u003cffff80008002b8dc\u003e] invoke_syscall+0x7c/0x104     [\u003cffff80008002ba44\u003e] el0_svc_common.constprop.1+0xe0/0x104     [\u003cffff80008002ba94\u003e] do_el0_svc+0x2c/0x38     [\u003cffff800081041108\u003e] el0_svc+0x3c/0x1b8  The opt-\u003eiocharset is freed inside the isofs_fill_super function, But there may be situations where it's not possible to enter this function.  For example, in the get_tree_bdev_flags function,when encountering the situation where \"Can't mount, would change RO state,\" In such a case, isofs_fill_super will not have the opportunity to be called,which means that opt-\u003eiocharset will not have the chance to be freed,ultimately leading to a memory leak.  Let's move the memory freeing of opt-\u003eiocharset into isofs_free_fc function.","modified":"2026-09-15T09:03:16.676734391Z","published":"2024-12-27T14:15:32.940Z","upstream":["CVE-2024-56534"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-56534"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56534.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56534.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}