CVE-2024-56661NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 27
Latest updateAug 14

Description

In the Linux kernel, the following vulnerability has been resolved: tipc: fix NULL deref in cleanup_bearer() syzbot found [1] that after blamed commit, ub->ubsock->sk was NULL when attempting the atomic_dec() : atomic_dec(&tipc_net(sock_net(ub->ubsock->sk))->wq_count); Fix this by caching the tipc_net pointer. [1] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000006: 0000 [#1] PREEMPT SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000030-0x000000

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Debianlinux/linux_kernel< 5.10.234-1+3
NVDlinux/linux_kernel7 versions+6
CVEListV5linux/linux4e69457f9dfae67435f3ccf29008768eae860415d1d4dfb189a115734bff81c411bc58d9e348db7d+12
debiandebian/linux< linux 6.1.123-1 (bookworm)
debiandebian/linux-6.1< linux 6.1.123-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4g6f-5r4h-c449: In the Linux kernel, the following vulnerability has been resolved: tipc: fix NULL deref in cleanup_bearer() syzbot found [1] that after blamed comm2024-12-27
OSV
CVE-2024-56661: In the Linux kernel, the following vulnerability has been resolved: tipc: fix NULL deref in cleanup_bearer() syzbot found [1] that after blamed commit2024-12-27

📋Vendor Advisories

3
CISA ICS
Siemens Third-Party Components in SINEC OS2025-08-14
Red Hat
kernel: tipc: fix NULL deref in cleanup_bearer()2024-12-27
Debian
CVE-2024-56661: linux - In the Linux kernel, the following vulnerability has been resolved: tipc: fix N...2024