Cyber Resilience

CVE-2024-26986

Linux Kernel 6.5 – 6.6.29

Published
01 May 2024
Modified
04 November 2025
Patch / advisory
CVSS Score v3.1 5.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0023 14th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2024-26986 is a medium-severity Missing Release of Memory after Effective Lifetime (CWE-401) vulnerability in Linux Linux Kernel. Its CVSS base score is 5.5 (Medium).

Operationally, ranked at the 14th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix memory leak in create_process failure Fix memory leak due to a leaked mmget reference on an error handling code path that is triggered when attempting to create KFD…

more

processes while a GPU reset is in progress.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-27012Same product: Fedoraproject Fedora
CVE-2024-27016Same product: Fedoraproject Fedora
CVE-2023-39197Same product: Fedoraproject Fedora
CVE-2023-3106Same product: Fedoraproject Fedora
CVE-2023-5345Same product: Fedoraproject Fedora
CVE-2024-27400Same product: Fedoraproject Fedora
CVE-2024-27017Same product: Fedoraproject Fedora
CVE-2023-5972Same product: Fedoraproject Fedora
CVE-2023-1194Same product: Fedoraproject Fedora
CVE-2024-1312Same product: Fedoraproject Fedora

Affected Assets

linux
linux kernel
6.9 · 6.5 — 6.6.29 · 6.7 — 6.8.8
fedoraproject
fedora
38, 39, 40

Mitigating Controls

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly enforce proper memory allocation/deallocation via coding standards, reviews, and tooling.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

detects

Security testing in development can detect unreleased memory, providing partial coverage of the weakness.

prevents

Secure development life cycle mandates memory-management practices that reduce missing-release defects.

prevents

Application security requirements can specify explicit memory-release rules, partially mitigating the weakness.

prevents

Secure system architecture and engineering principles include resource-management guidelines that address memory leaks.

prevents

Secure coding standards directly require proper allocation/deallocation, covering most of this weakness.

detects

Capacity management may detect memory exhaustion symptoms but does not prevent the coding flaw.

References