{"schema_version":"1.9.0","id":"CVE-2024-26839","published":"2024-04-17T10:10:05.536Z","modified":"2026-08-12T03:51:37.930237232Z","related":["SUSE-SU-2024:1643-1","SUSE-SU-2024:1646-1","SUSE-SU-2024:1870-1","SUSE-SU-2024:2008-1","SUSE-SU-2024:2019-1","SUSE-SU-2024:2190-1"],"summary":"IB/hfi1: Fix a memleak in init_credit_return","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Fix a memleak in init_credit_return\n\nWhen dma_alloc_coherent fails to allocate dd->cr_base[i].va,\ninit_credit_return should deallocate dd->cr_base and\ndd->cr_base[i] that allocated before. Or those resources\nwould be never freed and a memleak is triggered.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"7724105686e718ac476a6ad3304fea2fbcfcffde"},{"fixed":"2e4f9f20b32658ef3724aa46f7aef4908d2609e3"},{"fixed":"cecfb90cf71d91e9efebd68b9e9b84661b277cc8"},{"fixed":"3fa240bb6b2dbb3e7a3ee1440a4889cbb6207eb7"},{"fixed":"52de5805c147137205662af89ed7e083d656ae25"},{"fixed":"f0d857ce31a6bc7a82afcdbadb8f7417d482604b"},{"fixed":"b41d0ade0398007fb746213f09903d52a920e896"},{"fixed":"8412c86e89cc78d8b513cb25cf2157a2adf3670a"},{"fixed":"809aa64ebff51eb170ee31a95f83b2d21efa32e2"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26839.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.3.0"},{"fixed":"4.19.308"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"5.4.270"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.211"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.150"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.80"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.19"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.7.7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26839.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2e4f9f20b32658ef3724aa46f7aef4908d2609e3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3fa240bb6b2dbb3e7a3ee1440a4889cbb6207eb7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/52de5805c147137205662af89ed7e083d656ae25"},{"type":"WEB","url":"https://git.kernel.org/stable/c/809aa64ebff51eb170ee31a95f83b2d21efa32e2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8412c86e89cc78d8b513cb25cf2157a2adf3670a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b41d0ade0398007fb746213f09903d52a920e896"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cecfb90cf71d91e9efebd68b9e9b84661b277cc8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f0d857ce31a6bc7a82afcdbadb8f7417d482604b"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26839.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26839"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26839.json"}}