CVE-2024-56606

Source
https://cve.org/CVERecord?id=CVE-2024-56606
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-56606.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-56606
Downstream
Related
Published
2024-12-27T14:51:11.327Z
Modified
2026-03-11T07:48:38.043755Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
af_packet: avoid erroring out after sock_init_data() in packet_create()
Details

In the Linux kernel, the following vulnerability has been resolved:

afpacket: avoid erroring out after sockinitdata() in packetcreate()

After sockinitdata() the allocated sk object is attached to the provided sock object. On error, packet_create() frees the sk object leaving the dangling pointer in the sock object on return. Some other code may try to use this pointer and cause use-after-free.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56606.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b013840810c221f2b0cf641d01531526052dc1fb
Fixed
71b22837a5e55ac27d6a14b9cdf2326587405c4f
Fixed
1dc1e1db927056cb323296e2294a855cd003dfe7
Fixed
132e615bb1d7cdec2d3cfbdec2efa630e923fd21
Fixed
a6cf750b737374454a4e03a5ed449a3eb0c96414
Fixed
157f08db94123e2ba56877dd0ac88908b13a5dd0
Fixed
fd09880b16d33aa5a7420578e01cd79148fa9829
Fixed
46f2a11cb82b657fd15bab1c47821b635e03838b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-56606.json"