CVE-2024-56771

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 8, 2025
Updated: Jan 10, 2025

Summary

CVE-2024-56771 is a vulnerability affecting certain Linux kernel versions. Specifically, in the "mtd: spinand: winbond" driver, a problem with handling ECC (Error Correction Code) information for four specific Winbond chips (W25N512GW, W25N01GW, W25N01JW, and W25N02JW) has been identified. These chips, which all require a single bit of ECC strength, feature on-die Hamming-like ECC engines. Previously, the kernel attempted to fill a callback for getting status, but since the main ECC status bytes are located in standard places and the number of bitflips in case of corrected chunks is both useless and unsupported, this resulted in unnecessary kernel warnings every time a bit flipped. This issue has now been resolved.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share