CVE-2024-56672: blk-cgroup: Fix UAF in blkcg_unpin_online()
blk-cgroup: Fix UAF in blkcgunpinonline()
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade
Linux kernel blk-cgroupto a version that resolves this vulnerability.Fixed in 6.13.0-rc1-work-00182-gb8f52214c61a-dirty
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56672?
CVE-2024-56672 has been rated with a high severity level due to its potential to cause use-after-free issues in the Linux kernel.
How do I fix CVE-2024-56672?
To fix CVE-2024-56672, you should upgrade your Linux kernel to a version that includes the relevant patches addressing this vulnerability.
Which Linux kernel versions are affected by CVE-2024-56672?
CVE-2024-56672 affects Linux kernel versions between 5.7 and 6.1.121, and also versions between 6.2 and 6.6.67, as well as 6.7 to 6.12.6.
What is the impact of CVE-2024-56672 on system security?
The impact of CVE-2024-56672 can lead to memory corruption and potentially allow an attacker to execute arbitrary code in kernel mode.
Is CVE-2024-56672 a remote or local vulnerability?
CVE-2024-56672 is primarily considered a local vulnerability since it requires elevated privileges to exploit.