cbcvebase.
CVE-2024-56606
published 2024-12-27

CVE-2024-56606: In the Linux kernel, the following vulnerability has been resolved: af_packet: avoid erroring out after sock_init_data() in packet_create() After…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: af_packet: avoid erroring out after sock_init_data() in packet_create() After sock_init_data() the allocated sk object is attached to the provided sock object. On error, packet_create() frees the sk object leaving the dangling pointer in the sock object on return. Some other code may try to use this pointer and cause use-after-free.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= b013840810c221f2b0cf641d01531526052dc1fb < 71b22837a5e55ac27d6a14b9cdf2326587405c4f71b22837a5e55ac27d6a14b9cdf2326587405c4f
linuxlinux>= b013840810c221f2b0cf641d01531526052dc1fb < 1dc1e1db927056cb323296e2294a855cd003dfe71dc1e1db927056cb323296e2294a855cd003dfe7
linuxlinux>= b013840810c221f2b0cf641d01531526052dc1fb < 132e615bb1d7cdec2d3cfbdec2efa630e923fd21132e615bb1d7cdec2d3cfbdec2efa630e923fd21
linuxlinux>= b013840810c221f2b0cf641d01531526052dc1fb < a6cf750b737374454a4e03a5ed449a3eb0c96414a6cf750b737374454a4e03a5ed449a3eb0c96414
linuxlinux>= b013840810c221f2b0cf641d01531526052dc1fb < 157f08db94123e2ba56877dd0ac88908b13a5dd0157f08db94123e2ba56877dd0ac88908b13a5dd0
linuxlinux>= b013840810c221f2b0cf641d01531526052dc1fb < fd09880b16d33aa5a7420578e01cd79148fa9829fd09880b16d33aa5a7420578e01cd79148fa9829
linuxlinux>= b013840810c221f2b0cf641d01531526052dc1fb < 46f2a11cb82b657fd15bab1c47821b635e03838b46f2a11cb82b657fd15bab1c47821b635e03838b
linuxlinux_kernel< 5.4.2875.4.287
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 4.4.0-277.3114.4.0-277.311
linuxlinux_kernel>= 0 < 4.15.0-246.2584.15.0-246.258
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.2 < 6.6.666.6.66
linuxlinux_kernel>= 6.7 < 6.12.56.12.5

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.