SB2024123066 - Use-after-free in Linux kernel nfsd
Published: December 30, 2024 Updated: May 12, 2025
Security Bulletin ID
SB2024123066
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2024-56558)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the e_show() function in fs/nfsd/export.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1cecfdbc6bfc89c516d286884c7f29267b95de2b
- https://git.kernel.org/stable/c/6cefcadd34e3c71c81ea64b899a0daa86314a51a
- https://git.kernel.org/stable/c/7365d1f8de63cffdbbaa2287ce0205438e1a922f
- https://git.kernel.org/stable/c/7d8f7816bebcd2e7400bb4d786eccb8f33c9f9ec
- https://git.kernel.org/stable/c/7fd29d284b55c2274f7a748e6c5f25b4758b8da5
- https://git.kernel.org/stable/c/be8f982c369c965faffa198b46060f8853e0f1f0
- https://git.kernel.org/stable/c/e2fa0d0e327279a8defb87b263cd0bf288fd9261
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.287