PT-2024-36862 · Linux+8 · Linux Kernel+8
Yang Erkun
·
Published
2024-11-18
·
Updated
2025-10-03
·
CVE-2024-56558
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.12.0-rc3+
Description
A vulnerability has been resolved in the Linux kernel. The issue arises from the function
e show being called with protection from RCU, which only ensures that exp will not be freed. However, the reference count for exp can drop to zero, triggering a refcount use-after-free warning when exp get is called. To resolve this issue, cache get rcu is used to ensure that exp remains active. The vulnerability is related to the nfsd module and the svc export show function. Technical details include the e show function and the exp variable, as well as the cache get rcu function used to resolve the issue.Recommendations
To resolve this issue, update the Linux kernel to a version that includes the fix, which ensures that
exp remains active by using cache get rcu.
As a temporary workaround, consider restricting access to the vulnerable nfsd module until a patch is available.
Avoid using the e show function in the affected nfsd module until the issue is resolved.
At the moment, there is no information about additional mitigation measures.Exploit
Fix
Use After Free
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu