CVE-2024-56688 (GCVE-0-2024-56688)
Vulnerability from cvelistv5
Published
2024-12-28 09:46
Modified
2026-08-05 11:46
Summary
In the Linux kernel, the following vulnerability has been resolved: sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport Since transport->sock has been set to NULL during reset transport, XPRT_SOCK_UPD_TIMEOUT also needs to be cleared. Otherwise, the xs_tcp_set_socket_timeouts() may be triggered in xs_tcp_send_request() to dereference the transport->sock that has been set to NULL.
Impacted products
Vendor Product Version
Linux Linux Version: 7196dbb02ea05835b9ee56910ee82cb55422c7f1
Version: 7196dbb02ea05835b9ee56910ee82cb55422c7f1
Version: 7196dbb02ea05835b9ee56910ee82cb55422c7f1
Version: 7196dbb02ea05835b9ee56910ee82cb55422c7f1
Version: 7196dbb02ea05835b9ee56910ee82cb55422c7f1
Version: 7196dbb02ea05835b9ee56910ee82cb55422c7f1
Version: 7196dbb02ea05835b9ee56910ee82cb55422c7f1
Version: 7196dbb02ea05835b9ee56910ee82cb55422c7f1
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 5.5,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-56688",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-01T19:59:15.259954Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-476",
                "description": "CWE-476 NULL Pointer Dereference",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-01T20:07:08.414Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T20:52:34.192Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/sunrpc/xprtsock.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "cc91d59d34ff6a6fee1c0b48612081a451e05e9a",
              "status": "affected",
              "version": "7196dbb02ea05835b9ee56910ee82cb55422c7f1",
              "versionType": "git"
            },
            {
              "lessThan": "86a1f9fa24804cd7f9d7dd3f24af84fc7f8ec02e",
              "status": "affected",
              "version": "7196dbb02ea05835b9ee56910ee82cb55422c7f1",
              "versionType": "git"
            },
            {
              "lessThan": "fe6cbf0b2ac3cf4e21824a44eaa336564ed5e960",
              "status": "affected",
              "version": "7196dbb02ea05835b9ee56910ee82cb55422c7f1",
              "versionType": "git"
            },
            {
              "lessThan": "87a95ee34a48dfad198a2002e4966e1d63d53f2b",
              "status": "affected",
              "version": "7196dbb02ea05835b9ee56910ee82cb55422c7f1",
              "versionType": "git"
            },
            {
              "lessThan": "3811172e8c98ceebd12fe526ca6cb37a1263c964",
              "status": "affected",
              "version": "7196dbb02ea05835b9ee56910ee82cb55422c7f1",
              "versionType": "git"
            },
            {
              "lessThan": "638a8fa5a7e641f9401346c57e236f02379a0c40",
              "status": "affected",
              "version": "7196dbb02ea05835b9ee56910ee82cb55422c7f1",
              "versionType": "git"
            },
            {
              "lessThan": "66d11ca91bf5100ae2e6b5efad97e58d8448843a",
              "status": "affected",
              "version": "7196dbb02ea05835b9ee56910ee82cb55422c7f1",
              "versionType": "git"
            },
            {
              "lessThan": "4db9ad82a6c823094da27de4825af693a3475d51",
              "status": "affected",
              "version": "7196dbb02ea05835b9ee56910ee82cb55422c7f1",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/sunrpc/xprtsock.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.11"
            },
            {
              "lessThan": "4.11",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.287",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.231",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.174",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.120",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.64",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.13",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.287",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.231",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.174",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.120",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.64",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.11",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.2",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport\n\nSince transport-\u003esock has been set to NULL during reset transport,\nXPRT_SOCK_UPD_TIMEOUT also needs to be cleared. Otherwise, the\nxs_tcp_set_socket_timeouts() may be triggered in xs_tcp_send_request()\nto dereference the transport-\u003esock that has been set to NULL."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - Both halves of the trigger are driven by the remote NFS server over the network \u2014 it supplies the FSINFO/lease_time that sets XPRT_SOCK_UPD_TIMEOUT via nfs4_set_lease_period(), and it decides when to close or RST the TCP connection that runs xs_reset_transport(). An on-path attacker injecting RSTs into a long-lived NFSv4 connection can supply the reset half.\nAC:L - On 5.4.x/5.10.x xs_tcp_send_request() has no transport-\u003einet guard and xprt_sock_sendmsg() explicitly tolerates a NULL sock, so a stale flag plus one send on a torn-down transport is a deterministic oops; on 6.x the attacker controls both sides of the narrow window (callback traffic forces a send, RST forces the concurrent reset) and can retry on every reconnect.\nPR:N - The victim is the NFS client; a server does not authenticate to its clients, and the attacker needs no credentials or account on the target host \u2014 only the ability to answer RPCs on an existing mount or inject into its TCP connection.\nUI:N - No victim action is needed at exploitation time \u2014 an already-mounted NFSv4 share is a standing deployment condition, and the server drives the FSINFO refresh, callback traffic and connection reset on its own schedule.\nS:U - The NULL dereference occurs in the sunrpc transport code within the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:N - transport-\u003esock is exactly NULL and is dereferenced at a small fixed offset below mmap_min_addr; the fault aborts before any data is read, so nothing is disclosed.\nI:N - The access faults on an unmapped low address before any store completes \u2014 there is no attacker-controlled pointer, offset or value, hence no write primitive or data modification.\nA:H - A NULL pointer dereference in the RPC transmit path oopses the kernel while XPRT_LOCKED is held, permanently wedging the NFS mount and killing the rpciod/xprtiod worker; with panic_on_oops (common on embedded, automotive and appliance deployments) it is a full panic, and the server can repeat it on every reconnect."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:46:04.959Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cc91d59d34ff6a6fee1c0b48612081a451e05e9a"
        },
        {
          "url": "https://git.kernel.org/stable/c/86a1f9fa24804cd7f9d7dd3f24af84fc7f8ec02e"
        },
        {
          "url": "https://git.kernel.org/stable/c/fe6cbf0b2ac3cf4e21824a44eaa336564ed5e960"
        },
        {
          "url": "https://git.kernel.org/stable/c/87a95ee34a48dfad198a2002e4966e1d63d53f2b"
        },
        {
          "url": "https://git.kernel.org/stable/c/3811172e8c98ceebd12fe526ca6cb37a1263c964"
        },
        {
          "url": "https://git.kernel.org/stable/c/638a8fa5a7e641f9401346c57e236f02379a0c40"
        },
        {
          "url": "https://git.kernel.org/stable/c/66d11ca91bf5100ae2e6b5efad97e58d8448843a"
        },
        {
          "url": "https://git.kernel.org/stable/c/4db9ad82a6c823094da27de4825af693a3475d51"
        }
      ],
      "title": "sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-56688",
    "datePublished": "2024-12-28T09:46:14.905Z",
    "dateReserved": "2024-12-27T15:00:39.847Z",
    "dateUpdated": "2026-08-05T11:46:04.959Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T20:52:34.192Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.5, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-56688\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-10-01T19:59:15.259954Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-476\", \"description\": \"CWE-476 NULL Pointer Dereference\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-10-01T15:46:31.889Z\"}}], \"cna\": {\"title\": \"sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.5, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - Both halves of the trigger are driven by the remote NFS server over the network \\u2014 it supplies the FSINFO/lease_time that sets XPRT_SOCK_UPD_TIMEOUT via nfs4_set_lease_period(), and it decides when to close or RST the TCP connection that runs xs_reset_transport(). An on-path attacker injecting RSTs into a long-lived NFSv4 connection can supply the reset half.\\nAC:L - On 5.4.x/5.10.x xs_tcp_send_request() has no transport-\u003einet guard and xprt_sock_sendmsg() explicitly tolerates a NULL sock, so a stale flag plus one send on a torn-down transport is a deterministic oops; on 6.x the attacker controls both sides of the narrow window (callback traffic forces a send, RST forces the concurrent reset) and can retry on every reconnect.\\nPR:N - The victim is the NFS client; a server does not authenticate to its clients, and the attacker needs no credentials or account on the target host \\u2014 only the ability to answer RPCs on an existing mount or inject into its TCP connection.\\nUI:N - No victim action is needed at exploitation time \\u2014 an already-mounted NFSv4 share is a standing deployment condition, and the server drives the FSINFO refresh, callback traffic and connection reset on its own schedule.\\nS:U - The NULL dereference occurs in the sunrpc transport code within the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\\nC:N - transport-\u003esock is exactly NULL and is dereferenced at a small fixed offset below mmap_min_addr; the fault aborts before any data is read, so nothing is disclosed.\\nI:N - The access faults on an unmapped low address before any store completes \\u2014 there is no attacker-controlled pointer, offset or value, hence no write primitive or data modification.\\nA:H - A NULL pointer dereference in the RPC transmit path oopses the kernel while XPRT_LOCKED is held, permanently wedging the NFS mount and killing the rpciod/xprtiod worker; with panic_on_oops (common on embedded, automotive and appliance deployments) it is a full panic, and the server can repeat it on every reconnect.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"7196dbb02ea05835b9ee56910ee82cb55422c7f1\", \"lessThan\": \"cc91d59d34ff6a6fee1c0b48612081a451e05e9a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7196dbb02ea05835b9ee56910ee82cb55422c7f1\", \"lessThan\": \"86a1f9fa24804cd7f9d7dd3f24af84fc7f8ec02e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7196dbb02ea05835b9ee56910ee82cb55422c7f1\", \"lessThan\": \"fe6cbf0b2ac3cf4e21824a44eaa336564ed5e960\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7196dbb02ea05835b9ee56910ee82cb55422c7f1\", \"lessThan\": \"87a95ee34a48dfad198a2002e4966e1d63d53f2b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7196dbb02ea05835b9ee56910ee82cb55422c7f1\", \"lessThan\": \"3811172e8c98ceebd12fe526ca6cb37a1263c964\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7196dbb02ea05835b9ee56910ee82cb55422c7f1\", \"lessThan\": \"638a8fa5a7e641f9401346c57e236f02379a0c40\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7196dbb02ea05835b9ee56910ee82cb55422c7f1\", \"lessThan\": \"66d11ca91bf5100ae2e6b5efad97e58d8448843a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7196dbb02ea05835b9ee56910ee82cb55422c7f1\", \"lessThan\": \"4db9ad82a6c823094da27de4825af693a3475d51\", \"versionType\": \"git\"}], \"programFiles\": [\"net/sunrpc/xprtsock.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.11\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.11\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.4.287\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.231\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.174\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.120\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.64\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.11\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.13\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/sunrpc/xprtsock.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/cc91d59d34ff6a6fee1c0b48612081a451e05e9a\"}, {\"url\": \"https://git.kernel.org/stable/c/86a1f9fa24804cd7f9d7dd3f24af84fc7f8ec02e\"}, {\"url\": \"https://git.kernel.org/stable/c/fe6cbf0b2ac3cf4e21824a44eaa336564ed5e960\"}, {\"url\": \"https://git.kernel.org/stable/c/87a95ee34a48dfad198a2002e4966e1d63d53f2b\"}, {\"url\": \"https://git.kernel.org/stable/c/3811172e8c98ceebd12fe526ca6cb37a1263c964\"}, {\"url\": \"https://git.kernel.org/stable/c/638a8fa5a7e641f9401346c57e236f02379a0c40\"}, {\"url\": \"https://git.kernel.org/stable/c/66d11ca91bf5100ae2e6b5efad97e58d8448843a\"}, {\"url\": \"https://git.kernel.org/stable/c/4db9ad82a6c823094da27de4825af693a3475d51\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nsunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport\\n\\nSince transport-\u003esock has been set to NULL during reset transport,\\nXPRT_SOCK_UPD_TIMEOUT also needs to be cleared. Otherwise, the\\nxs_tcp_set_socket_timeouts() may be triggered in xs_tcp_send_request()\\nto dereference the transport-\u003esock that has been set to NULL.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.287\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.231\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.174\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.120\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.64\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.11\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.2\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.13\", \"versionStartIncluding\": \"4.11\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:46:04.959Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-56688\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:46:04.959Z\", \"dateReserved\": \"2024-12-27T15:00:39.847Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-12-28T09:46:14.905Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…