Fix memleak in ice_init_tx_topology() to avoid copying whole FW blob
CVE-2024-50190
What is CVE-2024-50190?
In the Linux kernel, the following vulnerability has been resolved:
ice: fix memleak in ice_init_tx_topology()
Fix leak of the FW blob (DDP pkg).
Make ice_cfg_tx_topo() const-correct, so ice_init_tx_topology() can avoid copying whole FW blob. Copy just the topology section, and only when needed. Reuse the buffer allocated for the read of the current topology.
This was found by kmemleak, with the following trace for each PF: [] kmemdup_noprof+0x1d/0x50 [] ice_init_ddp_config+0x100/0x220 [ice] [] ice_init_dev+0x6f/0x200 [ice] [] ice_init+0x29/0x560 [ice] [] ice_probe+0x21d/0x310 [ice]
Constify ice_cfg_tx_topo() @buf parameter. This cascades further down to few more functions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Linux cc5776fe183208115e42c044497e193e4671a2b9 < 43544b4e30732c3d88f423252281915d5bc739b6
Linux cc5776fe183208115e42c044497e193e4671a2b9
Linux 6.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved