cbcvebase.
CVE-2024-56573
published 2024-12-27

CVE-2024-56573: In the Linux kernel, the following vulnerability has been resolved: efi/libstub: Free correct pointer on failure cmdline_ptr is an out parameter, which is not…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.8th percentile
In the Linux kernel, the following vulnerability has been resolved: efi/libstub: Free correct pointer on failure cmdline_ptr is an out parameter, which is not allocated by the function itself, and likely points into the caller's stack. cmdline refers to the pool allocation that should be freed when cleaning up after a failure, so pass this instead to free_pool().

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.5-1 (forky)linux 6.12.5-1 (forky)
linuxlinux
linuxlinux>= 42c8ea3dca094ab82776ca706fb7a9cbe8ac3dc9 < d173aee5709bd0994d216d60589ec67f8b11376ad173aee5709bd0994d216d60589ec67f8b11376a
linuxlinux>= 42c8ea3dca094ab82776ca706fb7a9cbe8ac3dc9 < eaafbcf0a5782ae412ca7de12ef83fc48ccea4cfeaafbcf0a5782ae412ca7de12ef83fc48ccea4cf
linuxlinux>= 42c8ea3dca094ab82776ca706fb7a9cbe8ac3dc9 < 06d39d79cbd5a91a33707951ebf2512d0e75984706d39d79cbd5a91a33707951ebf2512d0e759847
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 6.2 < 6.6.646.6.64
linuxlinux_kernel>= 6.7 < 6.12.46.12.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.