cbcvebase.
CVE-2024-56739
published 2024-12-29

CVE-2024-56739: In the Linux kernel, the following vulnerability has been resolved: rtc: check if __rtc_read_time was successful in rtc_timer_do_work() If the __rtc_read_time…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.1th percentile
In the Linux kernel, the following vulnerability has been resolved: rtc: check if __rtc_read_time was successful in rtc_timer_do_work() If the __rtc_read_time call fails,, the struct rtc_time tm; may contain uninitialized data, or an illegal date/time read from the RTC hardware. When calling rtc_tm_to_ktime later, the result may be a very large value (possibly KTIME_MAX). If there are periodic timers in rtc->timerqueue, they will continually expire, may causing kernel softlockup.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 6610e0893b8bc6f59b14fed7f089c5997f035f88 < 39ad0a1ae17b54509cd9e93dcd8cec16e7c12d3f39ad0a1ae17b54509cd9e93dcd8cec16e7c12d3f
linuxlinux>= 6610e0893b8bc6f59b14fed7f089c5997f035f88 < 44b3257ff705d63d5f00ef8ed314a0eeb7ec37f244b3257ff705d63d5f00ef8ed314a0eeb7ec37f2
linuxlinux>= 6610e0893b8bc6f59b14fed7f089c5997f035f88 < 0d68e8514d9040108ff7d1b37ca71096674b6efe0d68e8514d9040108ff7d1b37ca71096674b6efe
linuxlinux>= 6610e0893b8bc6f59b14fed7f089c5997f035f88 < 246f621d363988e7040f4546d20203dc713fa3e1246f621d363988e7040f4546d20203dc713fa3e1
linuxlinux>= 6610e0893b8bc6f59b14fed7f089c5997f035f88 < fde56535505dde3336df438e949ef4742b6d6d6efde56535505dde3336df438e949ef4742b6d6d6e
linuxlinux>= 6610e0893b8bc6f59b14fed7f089c5997f035f88 < dd4b1cbcc916fad5d10c2662b62def9f05e453d4dd4b1cbcc916fad5d10c2662b62def9f05e453d4
linuxlinux>= 6610e0893b8bc6f59b14fed7f089c5997f035f88 < a1f0b4af90cc18b10261ecde56c6a56b22c75bd1a1f0b4af90cc18b10261ecde56c6a56b22c75bd1
linuxlinux>= 6610e0893b8bc6f59b14fed7f089c5997f035f88 < e77bce0a8c3989b4173c36f4195122bca8f4a3e1e77bce0a8c3989b4173c36f4195122bca8f4a3e1
linuxlinux>= 6610e0893b8bc6f59b14fed7f089c5997f035f88 < e8ba8a2bc4f60a1065f23d6a0e7cbea945a0f40de8ba8a2bc4f60a1065f23d6a0e7cbea945a0f40d
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 2.6.38 < 4.19.3254.19.325
linuxlinux_kernel>= 4.20 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.