cbcvebase.
CVE-2024-56645
published 2024-12-27

CVE-2024-56645: In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_session_new(): fix skb reference counting Since j1939_session_skb_queue()…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.68%
48.9th percentile
In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_session_new(): fix skb reference counting Since j1939_session_skb_queue() does an extra skb_get() for each new skb, do the same for the initial one in j1939_session_new() to avoid refcount underflow. [mkl: clean up commit message]

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 9d71dd0c70099914fcd063135da3c580865e924c < 224e606a8d8e8c7db94036272c47a37455667313224e606a8d8e8c7db94036272c47a37455667313
linuxlinux>= 9d71dd0c70099914fcd063135da3c580865e924c < b3282c2bebeeb82ceec492ee4972f51ee7a4a132b3282c2bebeeb82ceec492ee4972f51ee7a4a132
linuxlinux>= 9d71dd0c70099914fcd063135da3c580865e924c < 4199dd78a59896e091d3a7a05a77451aa7fd724d4199dd78a59896e091d3a7a05a77451aa7fd724d
linuxlinux>= 9d71dd0c70099914fcd063135da3c580865e924c < f117cba69cbbd496babb3defcdf440df4fd6fe14f117cba69cbbd496babb3defcdf440df4fd6fe14
linuxlinux>= 9d71dd0c70099914fcd063135da3c580865e924c < 426d94815e12b6bdb9a75af294fbbafb9301601d426d94815e12b6bdb9a75af294fbbafb9301601d
linuxlinux>= 9d71dd0c70099914fcd063135da3c580865e924c < 68fceb143b635cdc59fed3896d5910aff38f345e68fceb143b635cdc59fed3896d5910aff38f345e
linuxlinux>= 9d71dd0c70099914fcd063135da3c580865e924c < a8c695005bfe6569acd73d777ca298ddddd66105a8c695005bfe6569acd73d777ca298ddddd66105
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.4 < 5.4.2875.4.287
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.2 < 6.6.666.6.66
linuxlinux_kernel>= 6.7 < 6.12.56.12.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.