CVE-2024-56764
Published: Jan 6, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ublk: detach gendisk from ublk device if add_disk() fails Inside ublk_abort_requests(), gendisk is grabbed for aborting all inflight requests. And ublk_abort_requests() is called when exiting the uring context or handling timeout. If add_disk() fails, the gendisk may have been freed when calling ublk_abort_requests(), so use-after-free can be caused when getting disk's reference in ublk_abort_requests(). Fixes the bug by detaching gendisk from ublk device if add_disk() fails.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected bd23f6c2c2d00518e2f27f2d25cef795de9bee56 - < 7d680f2f76a3417fdfc3946da7471e81464f7b41affected bd23f6c2c2d00518e2f27f2d25cef795de9bee56 - < 75cd4005da5492129917a4a4ee45e81660556104 |
Linux | Linux | affected 6.7unaffected 0 - < 6.7unaffected 6.12.8 - <= 6.12.*unaffected 6.13 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now