Executive Summary

Informations
Name CVE-2024-56651 First vendor Publication 2024-12-27
Vendor Cve Last vendor Modification 2025-02-11

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Overall CVSS Score 7.8
Base Score 7.8 Environmental Score 7.8
impact SubScore 5.9 Temporal Score 7.8
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

can: hi311x: hi3110_can_ist(): fix potential use-after-free

The commit a22bd630cfff ("can: hi311x: do not report txerr and rxerr during bus-off") removed the reporting of rxerr and txerr even in case of correct operation (i. e. not bus-off).

The error count information added to the CAN frame after netif_rx() is a potential use after free, since there is no guarantee that the skb is in the same state. It might be freed or reused.

Fix the issue by postponing the netif_rx() call in case of txerr and rxerr reporting.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-56651

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-416 Use After Free

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3701

Sources (Detail)

https://git.kernel.org/stable/c/1128022009444faf49359bd406cd665b177cb643
https://git.kernel.org/stable/c/4ad77eb8f2e07bcfa0e28887d3c7dbb732d92cc1
https://git.kernel.org/stable/c/9ad86d377ef4a19c75a9c639964879a5b25a433b
https://git.kernel.org/stable/c/bc30b2fe8c54694f8ae08a5b8a5d174d16d93075
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
Date Informations
2025-07-15 02:41:12
  • Multiple Updates
2025-07-14 12:38:29
  • Multiple Updates
2025-06-26 02:38:27
  • Multiple Updates
2025-06-25 12:36:31
  • Multiple Updates
2025-06-24 02:43:05
  • Multiple Updates
2025-05-27 02:48:30
  • Multiple Updates
2025-03-29 03:44:24
  • Multiple Updates
2025-03-28 13:47:40
  • Multiple Updates
2025-03-28 03:22:13
  • Multiple Updates
2025-03-19 03:17:02
  • Multiple Updates
2025-03-18 03:30:01
  • Multiple Updates
2025-03-14 03:17:09
  • Multiple Updates
2025-03-06 14:13:41
  • Multiple Updates
2025-02-22 03:27:13
  • Multiple Updates
2025-02-11 21:20:53
  • Multiple Updates
2025-01-08 00:20:56
  • Multiple Updates
2025-01-07 03:08:11
  • Multiple Updates
2025-01-07 00:20:47
  • Multiple Updates
2024-12-27 21:20:28
  • First insertion