CVE-2024-56756

MEDIUM EPSS 11.9%
Published Dec 29, 20241y ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Dec 29, 2024 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix freeing of the HMB descriptor table The HMB descriptor table is sized to the maximum number of descriptors that could be used for a given device, but __nvme_alloc_host_mem could break out of the loop earlier on memory allocation failure and end up using less descriptors than planned for, which leads to an incorrect size passed to dma_free_coherent. In practice this was not showing up because the number of descriptors tends to be low and the dma coherent allocator always allocates and frees at least a page.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
11.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 7

VendorProductVersionRange
linuxlinux_kernel*≥4.13  –  <5.4.287
linuxlinux_kernel*≥5.5  –  <5.10.231
linuxlinux_kernel*≥5.11  –  <5.15.174
linuxlinux_kernel*≥5.16  –  <6.1.120
linuxlinux_kernel*≥6.2  –  <6.6.64
linuxlinux_kernel*≥6.7  –  <6.11.11
linuxlinux_kernel*≥6.12  –  <6.12.2

References 10

  • git.kernel.org https://git.kernel.org/stable/c/3c2fb1ca8086eb139b2a551358137525ae8e0d7a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/452f9ddd12bebc04cef741e8ba3806bf0e1fd015
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/582d9ed999b004fb1d415ecbfa86d4d8df455269
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6d0f599db73b099aa724a12736369c4d4d92849d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/869cf50b9c9d1059f5223f79ef68fc0bc6210095
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ac22240540e0c5230d8c4138e3778420b712716a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cee3bff51a35cab1c5d842d409a7b11caefe2386
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fb96d5cfa97a7363245b3dd523f475b04296d87b
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/3c2fb1ca8086eb139b2a551358137525ae8e0d7a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/452f9ddd12bebc04cef741e8ba3806bf0e1fd015
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/582d9ed999b004fb1d415ecbfa86d4d8df455269
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6d0f599db73b099aa724a12736369c4d4d92849d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/869cf50b9c9d1059f5223f79ef68fc0bc6210095
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ac22240540e0c5230d8c4138e3778420b712716a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cee3bff51a35cab1c5d842d409a7b11caefe2386
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fb96d5cfa97a7363245b3dd523f475b04296d87b
    Patch