#VU102245 Resource management error in Linux kernel - CVE-2024-56636
Published: December 30, 2024 / Updated: May 11, 2025
Vulnerability identifier: #VU102245
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-56636
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the geneve_xmit_skb() function in drivers/net/geneve.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
External links
- https://git.kernel.org/stable/c/177b72ed7c77b11e46dd4336d73a87a77a5603af
- https://git.kernel.org/stable/c/2ee7bdc7cb40abfe658a71fbd10c7db2f4fc4f9a
- https://git.kernel.org/stable/c/8588c99c7d47448fcae39e3227d6e2bb97aad86d
- https://git.kernel.org/stable/c/97ce3a4ec55eac6b5e2949ffb04028d604afda3b
- https://git.kernel.org/stable/c/b65958284401016b983078c68f70b047537f4aba
- https://git.kernel.org/stable/c/d9fa09ca004befe9cf826d6820439cb6f93cecd7
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.231