CVE-2024-56632

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Jan 14, 2025
CWE ID 401

Summary

CVE-2024-56632 is a vulnerability affecting the Linux kernel. This issue involves the nvme-tcp driver, where memory is not properly freed during the creation of a new controller. Specifically, the tagset associated with the admin queue is not released when controller creation fails. This oversight can lead to a memory leak. The Linux community has since addressed this issue by implementing proper memory management within the nvme-tcp driver to prevent potential memory exhaustion and system instability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share