cbcvebase.
CVE-2024-56662
published 2024-12-27

CVE-2024-56662: In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot…

PriorityP428medium6CVSS 3.1
AVLACLPRHUINSUCHINAH
EPSS
0.60%
45.2th percentile
In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot with KASAN: BUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/ core.c:416 [inline] BUG: KASAN: vmalloc-out-of-bounds in acpi_nfit_ctl+0x20e8/0x24a0 drivers/acpi/nfit/core.c:459 The issue occurs in cmd_to_func when the call_pkg->nd_reserved2 array is accessed without verifying that call_pkg points to a buffer that is appropriately sized as a struct nd_cmd_pkg. This can lead to out-of-bounds access and undefined behavior if the buffer does not have sufficient space. To address this, a check was added in acpi_nfit_ctl() to ensure that buf is not NULL and that buf_len is less than sizeof(*call_pkg) before accessing it. This ensures safe access to the members of call_pkg, including the nd_reserved2 array.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.176 < 4.154.15
linuxlinux>= 4.19.31 < 4.204.20
linuxlinux>= 5.0.4 < 5.15.1
linuxlinux>= ebe9f6f19d80d8978d16078dff3d5bd93ad8d102 < 616aa5f3c86e0479bcbb81e41c08c43ff32af637616aa5f3c86e0479bcbb81e41c08c43ff32af637
linuxlinux>= ebe9f6f19d80d8978d16078dff3d5bd93ad8d102 < bbdb3307f609ec4dc9558770f464ede01fe52aedbbdb3307f609ec4dc9558770f464ede01fe52aed
linuxlinux>= ebe9f6f19d80d8978d16078dff3d5bd93ad8d102 < 143f723e9eb4f0302ffb7adfdc7ef77eab3f68e0143f723e9eb4f0302ffb7adfdc7ef77eab3f68e0
linuxlinux>= ebe9f6f19d80d8978d16078dff3d5bd93ad8d102 < e08dc2dc3c3f7938df0e4476fe3e6fdec5583c1de08dc2dc3c3f7938df0e4476fe3e6fdec5583c1d
linuxlinux>= ebe9f6f19d80d8978d16078dff3d5bd93ad8d102 < 212846fafb753a48e869e2a342fc1e24048da771212846fafb753a48e869e2a342fc1e24048da771
linuxlinux>= ebe9f6f19d80d8978d16078dff3d5bd93ad8d102 < 265e98f72bac6c41a4492d3e30a8e5fd22fe0779265e98f72bac6c41a4492d3e30a8e5fd22fe0779
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 0 < 4.15.0-239.2514.15.0-239.251
linuxlinux_kernel>= 0 < 5.4.0-219.2395.4.0-219.239

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.1HIGH
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.