cbcvebase.
CVE-2024-56602
published 2024-12-27

CVE-2024-56602: In the Linux kernel, the following vulnerability has been resolved: net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() sock_init_data()…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() sock_init_data() attaches the allocated sk object to the provided sock object. If ieee802154_create() fails later, the allocated sk object is freed, but the dangling pointer remains in the provided sock object, which may allow use-after-free. Clear the sk pointer in the sock object on error.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 9ec7671603573ede31207eb5b0b3e1aa211b2854 < 1d5fe782c0ff068d80933f9cfd0fd39d5434bbc91d5fe782c0ff068d80933f9cfd0fd39d5434bbc9
linuxlinux>= 9ec7671603573ede31207eb5b0b3e1aa211b2854 < 14959fd7538b3be6d7617d9e60e404d6a8d4fd1f14959fd7538b3be6d7617d9e60e404d6a8d4fd1f
linuxlinux>= 9ec7671603573ede31207eb5b0b3e1aa211b2854 < 2b46994a6e76c8cc5556772932b9b60d03a55cd82b46994a6e76c8cc5556772932b9b60d03a55cd8
linuxlinux>= 9ec7671603573ede31207eb5b0b3e1aa211b2854 < e8bd6c5f5dc2234b4ea714380aedeea12a781754e8bd6c5f5dc2234b4ea714380aedeea12a781754
linuxlinux>= 9ec7671603573ede31207eb5b0b3e1aa211b2854 < b4982fbf13042e3bb33e04eddfea8b1506b5ea65b4982fbf13042e3bb33e04eddfea8b1506b5ea65
linuxlinux>= 9ec7671603573ede31207eb5b0b3e1aa211b2854 < 03caa9bfb9fde97fb53d33decd7364514e6825cb03caa9bfb9fde97fb53d33decd7364514e6825cb
linuxlinux>= 9ec7671603573ede31207eb5b0b3e1aa211b2854 < b4fcd63f6ef79c73cafae8cf4a114def5fc3d80db4fcd63f6ef79c73cafae8cf4a114def5fc3d80d
linuxlinux_kernel< 5.4.2875.4.287
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.2 < 6.6.666.6.66
linuxlinux_kernel>= 6.7 < 6.12.56.12.5
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.