Executive Summary

Informations
Name CVE-2024-56756 First vendor Publication 2024-12-29
Vendor Cve Last vendor Modification 2025-01-06

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

nvme-pci: fix freeing of the HMB descriptor table

The HMB descriptor table is sized to the maximum number of descriptors that could be used for a given device, but __nvme_alloc_host_mem could break out of the loop earlier on memory allocation failure and end up using less descriptors than planned for, which leads to an incorrect size passed to dma_free_coherent.

In practice this was not showing up because the number of descriptors tends to be low and the dma coherent allocator always allocates and frees at least a page.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-56756

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3670

Sources (Detail)

https://git.kernel.org/stable/c/3c2fb1ca8086eb139b2a551358137525ae8e0d7a
https://git.kernel.org/stable/c/452f9ddd12bebc04cef741e8ba3806bf0e1fd015
https://git.kernel.org/stable/c/582d9ed999b004fb1d415ecbfa86d4d8df455269
https://git.kernel.org/stable/c/6d0f599db73b099aa724a12736369c4d4d92849d
https://git.kernel.org/stable/c/869cf50b9c9d1059f5223f79ef68fc0bc6210095
https://git.kernel.org/stable/c/ac22240540e0c5230d8c4138e3778420b712716a
https://git.kernel.org/stable/c/cee3bff51a35cab1c5d842d409a7b11caefe2386
https://git.kernel.org/stable/c/fb96d5cfa97a7363245b3dd523f475b04296d87b
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
Date Informations
2025-02-22 03:27:25
  • Multiple Updates
2025-01-08 00:20:37
  • Multiple Updates
2025-01-07 03:08:06
  • Multiple Updates
2025-01-07 00:20:27
  • Multiple Updates
2024-12-29 17:20:29
  • First insertion