cbcvebase.
CVE-2024-56600
published 2024-12-27

CVE-2024-56600: In the Linux kernel, the following vulnerability has been resolved: net: inet6: do not leave a dangling sk pointer in inet6_create() sock_init_data() attaches…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: net: inet6: do not leave a dangling sk pointer in inet6_create() sock_init_data() attaches the allocated sk pointer to the provided sock object. If inet6_create() fails later, the sk object is released, but the sock object retains the dangling sk pointer, which may cause use-after-free later. Clear the sock sk pointer on error.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f2709d1271cfdf55c670ab5c5982139ab627ddc7f2709d1271cfdf55c670ab5c5982139ab627ddc7
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 35360255ca30776dee34d9fa764cffa24d0a5f6535360255ca30776dee34d9fa764cffa24d0a5f65
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 276a473c956fb55a6f3affa9ff232e10fffa7b43276a473c956fb55a6f3affa9ff232e10fffa7b43
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 79e16a0d339532ea832d85798eb036fc4f9e0cea79e16a0d339532ea832d85798eb036fc4f9e0cea
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 706b07b7b37f886423846cb38919132090bc40da706b07b7b37f886423846cb38919132090bc40da
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f44fceb71d72d29fb00e0ac84cdf9c081b03cd06f44fceb71d72d29fb00e0ac84cdf9c081b03cd06
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9df99c395d0f55fb444ef39f4d6f194ca437d8849df99c395d0f55fb444ef39f4d6f194ca437d884
linuxlinux_kernel< 5.4.2875.4.287
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 3.13.0-205.2563.13.0-205.256
linuxlinux_kernel>= 0 < 4.4.0-267.3014.4.0-267.301
linuxlinux_kernel>= 0 < 4.15.0-236.2484.15.0-236.248
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.2 < 6.6.666.6.66

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.