Review reviewHigh

CVE-2024-56651

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: can: hi311x: hi3110_can_ist(): fix potential use-after-free The commit a22bd630cfff ("can: hi311x: do not report txerr and rxerr during bus-off") removed the reporting of rxerr and txerr even in case of correct operation (i. e. not bus-off). The error count information added to the CAN frame after netif_rx() is a potential use after free, since there is no guarantee that the skb is in the same state. It might be freed or reused. Fix the issue by postponing the netif_rx() call in case of txerr and rxerr reporting.

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.12.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: can: hi311x: hi3110_can_ist(): fix potential use-after-free The commit a22bd630cfff ("can: hi311x: do not report txerr and rxerr during bus-off") removed the reporting of rxerr and txerr even in case of correct operation (i. e. not bus-off). The error count information added to the CAN frame after netif_rx() is a potential use after free, since there is no guarantee that the skb is in the same state. It might be freed or reused. Fix the issue by postponing the netif_rx() call in case of txerr and rxerr reporting.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= a22bd630cfff496b270211745536e50e98eb3a45 < 4ad77eb8f2e07bcfa0e28887d3c7dbb732d92cc1, >= a22bd630cfff496b270211745536e50e98eb3a45 < 1128022009444faf49359bd406cd665b177cb643, >= a22bd630cfff496b270211745536e50e98eb3a45 < bc30b2fe8c54694f8ae08a5b8a5d174d16d93075, >= a22bd630cfff496b270211745536e50e98eb3a45 < 9ad86d377ef4a19c75a9c639964879a5b25a433b, >= 303733fdab728d34708014b3096dc69ebae6e531, >= 410054f1cf75378a6f009359e5952a240102a1a2, >= d20bf7e76136fd4c1e47502a1f5773f2290013ed, >= 22e382d47de09e865a9214cc5c9f99256e65deaa, >= dcfcd5fc999b1eb7946de1fd031bc3aaf224c5ae, >= 330b0ac34beec4fef8b002549af5bc6d0b6f0836, >= f3d865a6b791abbc874739ed702ae64ad2607511, >= 4.14.291 < 4.15, >= 4.19.256 < 4.20, >= 5.4.211 < 5.5, >= 5.10.137 < 5.11, >= 5.15.61 < 5.16, >= 5.18.18 < 5.19, >= 5.19.2 < 5.20, >= 6.0, >= 6.0 < 6.1.120
Fixed versions
4.15, 4.20, 5.5, 5.11, 5.16, 5.19, 5.20, 6.1.120, 6.6.66, 6.12.5

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416