CVE-2024-41023 is a memory leak in the Linux kernel deadline scheduler. start_dl_timer() acquires a task_struct reference and starts a timer whose dl_task_timer callback normally releases that reference on expiration. If enqueue_task_dl() cancels the timer before expiration, the acquired reference is not released, preventing reclamation of the task structure. The defect was repeatedly observed during cyclic stress testing on linux-rt. The fix releases the task_struct reference when the timer is canceled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel deadline-scheduler vulnerability causes a task_struct memory leak when enqueue_task_dl() cancels a timer established by start_dl_timer() without releasing the associated reference. The patch ensures the reference count is decremented when the timer is canceled. The advisory rates the vulnerability Medium, with a CVSS v3 base score of 6.1, and directs affected Google COS kernel packages to be updated to version 19165.0.0 or later.
A reference-counting flaw in the Linux kernel deadline scheduler causes task_struct memory leaks when enqueue_task_dl() cancels a timer before its callback can release the reference. The patch ensures the reference count is decremented when the timer is canceled. The advisory rates the vulnerability Medium, with a CVSS v3 base score of 6.1 and high availability impact. It recommends updating Echo linux and related packages to version 6.9.10-1 or later.
Linux kernel vulnerability covered by the security update.
Linux kernel deadline scheduler task_struct reference-leak issue.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.