cbcvebase.
CVE-2024-56603
published 2024-12-27

CVE-2024-56603: In the Linux kernel, the following vulnerability has been resolved: net: af_can: do not leave a dangling sk pointer in can_create() On error can_create() frees…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net: af_can: do not leave a dangling sk pointer in can_create() On error can_create() frees the allocated sk object, but sock_init_data() has already attached it to the provided sock object. This will leave a dangling sk pointer in the sock object and may cause use-after-free later.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 0d66548a10cbbe0ef256852d63d30603f0f73f9b < 884ae8bcee749be43a071d6ed2d89058dbd2425c884ae8bcee749be43a071d6ed2d89058dbd2425c
linuxlinux>= 0d66548a10cbbe0ef256852d63d30603f0f73f9b < ce39b5576785bb3e66591145aad03d66bc3e778dce39b5576785bb3e66591145aad03d66bc3e778d
linuxlinux>= 0d66548a10cbbe0ef256852d63d30603f0f73f9b < 1fe625f12d090d69f3f084990c7e4c1ff94bfe5f1fe625f12d090d69f3f084990c7e4c1ff94bfe5f
linuxlinux>= 0d66548a10cbbe0ef256852d63d30603f0f73f9b < 5947c9ac08f0771ea8ed64186b0d52e9029cb6c05947c9ac08f0771ea8ed64186b0d52e9029cb6c0
linuxlinux>= 0d66548a10cbbe0ef256852d63d30603f0f73f9b < db207d19adbac96058685f6257720906ad41d215db207d19adbac96058685f6257720906ad41d215
linuxlinux>= 0d66548a10cbbe0ef256852d63d30603f0f73f9b < 8df832e6b945e1ba61467d7f1c9305e314ae92fe8df832e6b945e1ba61467d7f1c9305e314ae92fe
linuxlinux>= 0d66548a10cbbe0ef256852d63d30603f0f73f9b < 811a7ca7320c062e15d0f5b171fe6ad8592d1434811a7ca7320c062e15d0f5b171fe6ad8592d1434
linuxlinux_kernel< 5.4.2875.4.287
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.2 < 6.6.666.6.66
linuxlinux_kernel>= 6.7 < 6.12.56.12.5
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.