cbcvebase.
CVE-2024-56783
published 2025-01-08

CVE-2024-56783: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level cgroup maximum depth is…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.6th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level cgroup maximum depth is INT_MAX by default, there is a cgroup toggle to restrict this maximum depth to a more reasonable value not to harm performance. Remove unnecessary WARN_ON_ONCE which is reachable from userspace.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 6.1.112 < 6.1.1206.1.120
linuxlinux>= 6.10.12 < 6.116.11
linuxlinux>= 6.6.53 < 6.6.666.6.66
linuxlinux>= 7f3287db654395f9c5ddd246325ff7889f550286 < e227c042580ab065edc610c9ddc9bea691e6fc4de227c042580ab065edc610c9ddc9bea691e6fc4d
linuxlinux>= 7f3287db654395f9c5ddd246325ff7889f550286 < b7529880cb961d515642ce63f9d7570869bbbdc3b7529880cb961d515642ce63f9d7570869bbbdc3
linuxlinux>= ace0db36b4a1db07a48517c4f04488d1cd05e5f5 < 7064a6daa4a700a298fe3aee11dea296bfe59fc47064a6daa4a700a298fe3aee11dea296bfe59fc4
linuxlinux>= f07e28e4c623168f9fa5c00f518bd341d4014aa6 < 2f9bec0a749eb646b384fde0c7b7c24687b2ffae2f9bec0a749eb646b384fde0c7b7c24687b2ffae
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 6.1.112 < 6.1.1206.1.120
linuxlinux_kernel>= 6.10.12 < 6.12.56.12.5
linuxlinux_kernel>= 6.6.53 < 6.6.666.6.66

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.