Review reviewHigh

CVE-2024-56631

Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Fix slab-use-after-free read in sg_release() Fix a use-after-free bug in sg_release(), detected by syzbot with KASAN: BUG: KASAN: slab-use-after-free in lock_release+0x151/0xa30 kernel/locking/lockdep.c:5838 __mutex_unlock_slowpath+0xe2/0x750 kernel/locking/mutex.c:912 sg_release+0x1f4/0x2e0 drivers/scsi/sg.c:407 In sg_release(), the function kref_put(&sfp->f_ref, sg_remove_sfp) is called before releasing the open_rel_lock mutex. The kref_put() call may decrement the reference count of sfp to zero, triggering its...

CVSS
7.8
EPSS
0.29%
20.8% percentile
CISA KEV
Not listed
Published
2024.12.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.29%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Fix slab-use-after-free read in sg_release() Fix a use-after-free bug in sg_release(), detected by syzbot with KASAN: BUG: KASAN: slab-use-after-free in lock_release+0x151/0xa30 kernel/locking/lockdep.c:5838 __mutex_unlock_slowpath+0xe2/0x750 kernel/locking/mutex.c:912 sg_release+0x1f4/0x2e0 drivers/scsi/sg.c:407 In sg_release(), the function kref_put(&sfp->f_ref, sg_remove_sfp) is called before releasing the open_rel_lock mutex. The kref_put() call may decrement the reference count of sfp to zero, triggering its...

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Affected versions
>= cc833acbee9db5ca8c6162b015b4c93863c6f821 < e19acb1926c4a1f30ee1ec84d8afba2d975bd534, >= cc833acbee9db5ca8c6162b015b4c93863c6f821 < 285ce1f89f8d414e7eecab5ef5118cd512596318, >= cc833acbee9db5ca8c6162b015b4c93863c6f821 < 198b89dd5a595ee3f96e5ce5c448b0484cd0e53c, >= cc833acbee9db5ca8c6162b015b4c93863c6f821 < 275b8347e21ab8193e93223a8394a806e4ba8918, >= cc833acbee9db5ca8c6162b015b4c93863c6f821 < 59b30afa578637169e2819536bb66459fdddc39d, >= cc833acbee9db5ca8c6162b015b4c93863c6f821 < 1f5e2f1ca5875728fcf62bc1a054707444ab4960, >= cc833acbee9db5ca8c6162b015b4c93863c6f821 < f10593ad9bc36921f623361c9e3dd96bd52d85ee, >= 3a27c0defb0315760100f8b1adc7c4acbe04c884, >= 3.16.85 < 3.17, >= 3.17, >= V3.1.6, >= 3.16.85 < 6.6.66, >= 6.7 < 6.12.5, 6.13
Fixed versions
6.6.66, 6.12.5

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416