cbcvebase.
CVE-2024-56681
published 2024-12-28

CVE-2024-56681: In the Linux kernel, the following vulnerability has been resolved: crypto: bcm - add error check in the ahash_hmac_init function The ahash_init functions may…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.3th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: bcm - add error check in the ahash_hmac_init function The ahash_init functions may return fails. The ahash_hmac_init should not return ok when ahash_init returns error. For an example, ahash_init will return -ENOMEM when allocation memory is error.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < 8f1a9a960b1107bd0e0ec3736055f5ed0e717edf8f1a9a960b1107bd0e0ec3736055f5ed0e717edf
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < 75e1e38e5d80d6d9011b7322698ffba3dd3db30a75e1e38e5d80d6d9011b7322698ffba3dd3db30a
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < 28f8ffa945f7d7150463e15097ea73b19529d6f528f8ffa945f7d7150463e15097ea73b19529d6f5
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < 4ea3e3b761e371102bb1486778e2f8dbc9e374134ea3e3b761e371102bb1486778e2f8dbc9e37413
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < 05f0a3f5477ecaa1cf46448504afe9e7c2e96fcc05f0a3f5477ecaa1cf46448504afe9e7c2e96fcc
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < ae5253313e0ea5f00c06176074592b7f493c8546ae5253313e0ea5f00c06176074592b7f493c8546
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < ee36db8e8203420e6d5c42eb9428920c2fc36532ee36db8e8203420e6d5c42eb9428920c2fc36532
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < bba9e38c5ad41d0a88b22a59e5b6dd3e31825118bba9e38c5ad41d0a88b22a59e5b6dd3e31825118
linuxlinux>= 9d12ba86f818aa9cfe9f01b750336aa441f2ffa2 < 19630cf57233e845b6ac57c9c969a4888925467b19630cf57233e845b6ac57c9c969a4888925467b
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.11 < 4.19.3254.19.325
linuxlinux_kernel>= 4.20 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.