cbcvebase.
CVE-2024-56651
published 2024-12-27

CVE-2024-56651: In the Linux kernel, the following vulnerability has been resolved: can: hi311x: hi3110_can_ist(): fix potential use-after-free The commit a22bd630cfff ("can…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: can: hi311x: hi3110_can_ist(): fix potential use-after-free The commit a22bd630cfff ("can: hi311x: do not report txerr and rxerr during bus-off") removed the reporting of rxerr and txerr even in case of correct operation (i. e. not bus-off). The error count information added to the CAN frame after netif_rx() is a potential use after free, since there is no guarantee that the skb is in the same state. It might be freed or reused. Fix the issue by postponing the netif_rx() call in case of txerr and rxerr reporting.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.291 < 4.154.15
linuxlinux>= 4.19.256 < 4.204.20
linuxlinux>= 5.10.137 < 5.115.11
linuxlinux>= 5.15.61 < 5.165.16
linuxlinux>= 5.18.18 < 5.195.19
linuxlinux>= 5.19.2 < 5.205.20
linuxlinux>= 5.4.211 < 5.55.5
linuxlinux>= a22bd630cfff496b270211745536e50e98eb3a45 < 4ad77eb8f2e07bcfa0e28887d3c7dbb732d92cc14ad77eb8f2e07bcfa0e28887d3c7dbb732d92cc1
linuxlinux>= a22bd630cfff496b270211745536e50e98eb3a45 < 1128022009444faf49359bd406cd665b177cb6431128022009444faf49359bd406cd665b177cb643
linuxlinux>= a22bd630cfff496b270211745536e50e98eb3a45 < bc30b2fe8c54694f8ae08a5b8a5d174d16d93075bc30b2fe8c54694f8ae08a5b8a5d174d16d93075
linuxlinux>= a22bd630cfff496b270211745536e50e98eb3a45 < 9ad86d377ef4a19c75a9c639964879a5b25a433b9ad86d377ef4a19c75a9c639964879a5b25a433b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.