cbcvebase.
CVE-2024-56766
published 2025-01-06

CVE-2024-56766: In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix double free in atmel_pmecc_create_user() The "user" pointer was converted…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.8th percentile
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix double free in atmel_pmecc_create_user() The "user" pointer was converted from being allocated with kzalloc() to being allocated by devm_kzalloc(). Calling kfree(user) will lead to a double free.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 22fbbc37edb840fd420fadf670366be9bf028426 < ca9818554b0f33e87f38e4bfa2dac056692d46ccca9818554b0f33e87f38e4bfa2dac056692d46cc
linuxlinux>= 24cbc37e837fd9e31e5024480b779207d1d99f1d < 6ea15205d7e2b811fbbdf79783f686f58abfb4b76ea15205d7e2b811fbbdf79783f686f58abfb4b7
linuxlinux>= 4.19.325 < 4.204.20
linuxlinux>= 5.10.231 < 5.10.2335.10.233
linuxlinux>= 5.15.174 < 5.15.1765.15.176
linuxlinux>= 5.4.287 < 5.4.2895.4.289
linuxlinux>= 54cb5fa850f9306d84e49a3db44b7a7eb5536cd1 < 1562871ef613fa9492aa0310933eff785166a90e1562871ef613fa9492aa0310933eff785166a90e
linuxlinux>= 5fe7709251e334cc27618473299c48340cecd3c8 < 3d825a241e65f7e3072978729e79d735ec40b80e3d825a241e65f7e3072978729e79d735ec40b80e
linuxlinux>= 6.1.120 < 6.1.1236.1.123
linuxlinux>= 6.11.11 < 6.126.12
linuxlinux>= 6.12.2 < 6.12.86.12.8
linuxlinux>= 6.6.64 < 6.6.696.6.69
linuxlinux>= 6d734f1bfc336aaea91313a5632f2f197608fadd < d8e4771f99c0400a1873235704b28bb803c83d17d8e4771f99c0400a1873235704b28bb803c83d17
linuxlinux>= 8ac19ec818c548c5788da5926dcc8af96fad4bb1 < d2f090ea57f8d6587e09d4066f740a8617767b3dd2f090ea57f8d6587e09d4066f740a8617767b3d
linuxlinux>= f1290871c8aaeb13029390a2b6e5c05733a1be6f < dd45c87782738715d5e7c167f8dabf0814a7394add45c87782738715d5e7c167f8dabf0814a7394a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 4.19.325 < 4.204.20

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.