U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-56708

Change History

New CVE Received from kernel.org 12/28/2024 5:15:20 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

EDAC/igen6: Avoid segmentation fault on module unload

The segmentation fault happens because:

During modprobe:
1. In igen6_probe(), igen6_pvt will be allocated with kzalloc()
2. In igen6_register_mci(), mci->pvt_info will point to
   &igen6_pvt->imc[mc]

During rmmod:
1. In mci_release() in edac_mc.c, it will kfree(mci->pvt_info)
2. In igen6_remove(), it will kfree(igen6_pvt);

Fix this issue by setting mci->pvt_info to NULL to avoid the double
kfree.
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/029ac07bb92d2f7502d47a4916f197a8445d83bf
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/2a80e710bbc088a2511c159ee4d910456c5f0832
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/830cabb61113d92a425dd3038ccedbdfb3c8d079
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/db60326f2c47b079e36785ace621eb3002db2088
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/e5c7052664b61f9e2f896702d20552707d0ef60a
Added Reference

								
							
							
						
https://git.kernel.org/stable/c/fefaae90398d38a1100ccd73b46ab55ff4610fba