CVE-2024-44969: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Prevent release of buffer in I/O When a task waiting for completion of a Store Data operation is interrupted, an attempt is made to halt this operation. If this attempt fails due to a hardware or firmware problem, there is a chance that the SCLP facility might store data into buffers referenced by the original operation at a later time. Handle this situation by not releasing the referenced data buffers if the halt attempt fails. For current use cases, this might result in a leak of few pages of memory in case of a rare hardware/firmware malfunction.

Affected products

  • Linux Linux Kernel: before 4.19.320 (fixed in 4.19.320); from 4.20, before 5.4.282 (fixed in 5.4.282); from 5.5, before 5.10.224 (fixed in 5.10.224); from 5.11, before 5.15.165 (fixed in 5.15.165); from 5.16, before 6.1.105 (fixed in 6.1.105); from 6.2, before 6.6.46 (fixed in 6.6.46); …

Published 2024-09-04. Last modified 2026-06-17.