CVE-2024-56652
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Dec 27, 2024
Updated: Feb 11, 2025
CWE ID 416
Summary
CVE-2024-56652 is a use-after-free vulnerability identified in the Linux kernel's drm/xe/reg_sr module. The vulnerability arises due to an issue with a register pool implementation, which can lead to memory being moved and invalidating entries in the xarray, resulting in use-after-free later. The bug has been traced to a specific allocation and is attributed to task modprobe. To mitigate this issue, the code has been simplified as a temporary fix, and a more robust pooling strategy may be considered for future implementation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX