PT-2024-36957 · Linux +6 · Linux Kernel +6
Syzbot
·
Published
2024-11-26
·
Updated
2025-05-26
·
CVE-2024-56648
5.5
Medium
Base vector | Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.74
Description:
A potential out-of-bound access issue has been identified in the Linux kernel, specifically in the `fill frame info()` function. This issue can be triggered by sending a packet with 14 bytes, pretending to be a VLAN packet. The `fill frame info()` function relies on `skb->mac len`, and the check has been extended to cover this case. The issue is related to an uninit-value in `fill frame info()` and `hsr forward skb()`.
Recommendations:
Update to Linux kernel version 6.6.74 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable `fill frame info()` function until a patch is available.
Exploit
Fix
Use of Uninitialized Resource
Weakness Enumeration
Related Identifiers
Affected Products
References · 4630
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/cve_2022_0995_watch_queue.rb⭐ 35496 🔗 14298 · Exploit
- 🔥 https://github.com/Bonfee/CVE-2022-0995⭐ 497 🔗 67 · Exploit
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57935 · Security Note
- https://safe-surf.ru/specialists/bulletins-nkcki/721351 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50082 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50112 · Security Note
- https://ubuntu.com/security/CVE-2024-56575 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50063 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-53230 · Security Note
- https://bdu.fstec.ru/vul/2025-01786 · Security Note
- https://safe-surf.ru/specialists/bulletins-nkcki/721321 · Security Note
- https://ubuntu.com/security/CVE-2024-56639 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-07837 · Security Note
- https://ubuntu.com/security/CVE-2024-50057 · Vendor Advisory
- https://bdu.fstec.ru/vul/2024-04218 · Security Note