cbcvebase.
CVE-2024-56690
published 2024-12-28

CVE-2024-56690: In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY Since…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.6th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY Since commit 8f4f68e788c3 ("crypto: pcrypt - Fix hungtask for PADATA_RESET"), the pcrypt encryption and decryption operations return -EAGAIN when the CPU goes online or offline. In alg_test(), a WARN is generated when pcrypt_aead_decrypt() or pcrypt_aead_encrypt() returns -EAGAIN, the unnecessary panic will occur when panic_on_warn set 1. Fix this issue by calling crypto layer directly without parallelization in that case.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 039fec48e062504f14845124a1a25eb199b2ddc0 < dd8bf8eb5beba1e7c3b11a9a5a58ccbf345a69e6dd8bf8eb5beba1e7c3b11a9a5a58ccbf345a69e6
linuxlinux>= 372636debe852913529b1716f44addd94fff2d28 < 5edae7a9a35606017ee6e05911c290acee9fee5a5edae7a9a35606017ee6e05911c290acee9fee5a
linuxlinux>= 4.14.331 < 4.154.15
linuxlinux>= 4.19.300 < 4.19.3254.19.325
linuxlinux>= 5.10.202 < 5.10.2315.10.231
linuxlinux>= 5.15.140 < 5.15.1745.15.174
linuxlinux>= 5.4.262 < 5.4.2875.4.287
linuxlinux>= 546c1796ad1ed0d87dab3c4b5156d75819be2316 < 96001f52ae8c70e2c736d3e1e5dc53d5b521e5ca96001f52ae8c70e2c736d3e1e5dc53d5b521e5ca
linuxlinux>= 6.1.64 < 6.1.1206.1.120
linuxlinux>= 6.5.13 < 6.66.6
linuxlinux>= 6.6.3 < 6.6.646.6.64
linuxlinux>= 8f4f68e788c3a7a696546291258bfa5fdb215523 < a8e0074ffb38c9a5964a221bb998034d016c93a2a8e0074ffb38c9a5964a221bb998034d016c93a2
linuxlinux>= 8f4f68e788c3a7a696546291258bfa5fdb215523 < 7ddab756f2de5b7b43c122ebebdf37f400fb2b6f7ddab756f2de5b7b43c122ebebdf37f400fb2b6f
linuxlinux>= 8f4f68e788c3a7a696546291258bfa5fdb215523 < 662f2f13e66d3883b9238b0b96b17886179e60e2662f2f13e66d3883b9238b0b96b17886179e60e2
linuxlinux>= c55fc098fd9d2dca475b82d00ffbcaf97879d77e < 92834692a539b5b7f409e467a14667d64713b73292834692a539b5b7f409e467a14667d64713b732
linuxlinux>= c9c1334697301c10e6918d747ed38abfbc0c96e7 < fca8aed12218f96b38e374ff264d78ea1fbd23ccfca8aed12218f96b38e374ff264d78ea1fbd23cc
linuxlinux>= e97bf4ada7dddacd184c3e196bd063b0dc71b41d < a92ccd3618e42333ac6f150ecdac14dca298bc7aa92ccd3618e42333ac6f150ecdac14dca298bc7a
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.