CVE-2024-56632
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Dec 27, 2024
Updated: Jan 14, 2025
CWE ID 401
Summary
CVE-2024-56632 is a vulnerability affecting the Linux kernel. This issue involves the nvme-tcp driver, where memory is not properly freed during the creation of a new controller. Specifically, the tagset associated with the admin queue is not released when controller creation fails. This oversight can lead to a memory leak. The Linux community has since addressed this issue by implementing proper memory management within the nvme-tcp driver to prevent potential memory exhaustion and system instability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX