CVE Database
/

CVE-2024-56764

Back to search

CVE-2024-56764

Published: Jan 6, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: ublk: detach gendisk from ublk device if add_disk() fails Inside ublk_abort_requests(), gendisk is grabbed for aborting all inflight requests. And ublk_abort_requests() is called when exiting the uring context or handling timeout. If add_disk() fails, the gendisk may have been freed when calling ublk_abort_requests(), so use-after-free can be caused when getting disk's reference in ublk_abort_requests(). Fixes the bug by detaching gendisk from ublk device if add_disk() fails.

VendorProductVersions

Linux

Linux

affected
bd23f6c2c2d00518e2f27f2d25cef795de9bee56 - < 7d680f2f76a3417fdfc3946da7471e81464f7b41
affected
bd23f6c2c2d00518e2f27f2d25cef795de9bee56 - < 75cd4005da5492129917a4a4ee45e81660556104

Linux

Linux

affected
6.7
unaffected
0 - < 6.7
unaffected
6.12.8 - <= 6.12.*
unaffected
6.13 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now