cbcvebase.
CVE-2024-56601
published 2024-12-27

CVE-2024-56601: In the Linux kernel, the following vulnerability has been resolved: net: inet: do not leave a dangling sk pointer in inet_create() sock_init_data() attaches…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: net: inet: do not leave a dangling sk pointer in inet_create() sock_init_data() attaches the allocated sk object to the provided sock object. If inet_create() fails later, the sk object is freed, but the sock object retains the dangling pointer, which may create use-after-free later. Clear the sk pointer in the sock object on error.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f8a3f255f7509a209292871715cda03779640c8df8a3f255f7509a209292871715cda03779640c8d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2bc34d8c8898ae9fddf4612501aabb22d76c2b2c2bc34d8c8898ae9fddf4612501aabb22d76c2b2c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3e8258070b0f2aba66b3ef18883de229674fb2883e8258070b0f2aba66b3ef18883de229674fb288
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b4513cfd3a10c03c660d5d3d26c2e322efbfdd9bb4513cfd3a10c03c660d5d3d26c2e322efbfdd9b
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 25447c6aaa7235f155292b0c58a067347e8ae89125447c6aaa7235f155292b0c58a067347e8ae891
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 691d6d816f93b2a1008c14178399061466e674ef691d6d816f93b2a1008c14178399061466e674ef
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9365fa510c6f82e3aa550a09d0c5c6b44dbc78ff9365fa510c6f82e3aa550a09d0c5c6b44dbc78ff
linuxlinux_kernel< 5.4.2875.4.287
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.2 < 6.6.666.6.66
linuxlinux_kernel>= 6.7 < 6.12.56.12.5
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.