CVE-2024-56748

MEDIUM EPSS 12.4%
Published Dec 29, 20241y ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Dec 29, 2024 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb() Hook "qed_ops->common->sb_init = qed_sb_init" does not release the DMA memory sb_virt when it fails. Add dma_free_coherent() to free it. This is the same way as qedr_alloc_mem_sb() and qede_alloc_mem_sb().

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
12.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-401

Affected Products 7

VendorProductVersionRange
linuxlinux_kernel*≥4.11  –  <5.4.287
linuxlinux_kernel*≥5.5  –  <5.10.231
linuxlinux_kernel*≥5.11  –  <5.15.174
linuxlinux_kernel*≥5.16  –  <6.1.120
linuxlinux_kernel*≥6.2  –  <6.6.64
linuxlinux_kernel*≥6.7  –  <6.11.11
linuxlinux_kernel*≥6.12  –  <6.12.2

References 10

  • git.kernel.org https://git.kernel.org/stable/c/0e04bd5a11dffe8c1c0e4c9fc79f7d3cd6182dd5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/64654bf5efb3f748e6fc41227adda689618ce9c4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/78a169dc69fbdaf114c40e2d56955bf6bd4fc3c0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7c1832287b21ff68c4e3625e63cc7619edf5908b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/97384449ddfc07f12ca75f510eb070020d7abb34
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a56777a3ef5b35e24a20c4418bcf88bad033807a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b514f45e0fe18d763a1afc34401b1585333cb329
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c62c30429db3eb4ced35c7fcf6f04a61ce3a01bb
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0e04bd5a11dffe8c1c0e4c9fc79f7d3cd6182dd5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/64654bf5efb3f748e6fc41227adda689618ce9c4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/78a169dc69fbdaf114c40e2d56955bf6bd4fc3c0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7c1832287b21ff68c4e3625e63cc7619edf5908b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/97384449ddfc07f12ca75f510eb070020d7abb34
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a56777a3ef5b35e24a20c4418bcf88bad033807a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b514f45e0fe18d763a1afc34401b1585333cb329
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c62c30429db3eb4ced35c7fcf6f04a61ce3a01bb
    Patch