Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-56619

7.8 · HIGH
Published Dec 27, 2024 linux CWE-416 EPSS 0.21% (11th pctl)

Overview

CVE-2024-56619 is a high-severity vulnerability affecting linux linux_kernel. It was published on December 27, 2024 and has a CVSS 3.1 base score of 7.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix potential out-of-bounds memory access in nilfs_find_entry()

Syzbot reported that when searching for records in a directory where the

inode's i_size is corrupted and has a large value, memory access outside

the folio/page range may occur, or a use-after-free bug may be detected if

KASAN is enabled.

This is because nilfs_last_byte(), which is called by nilfs_find_entry()

and others to calculate the number of valid bytes of directory data in a

page from i_size and the page index, loses the upper 32 bits of the 64-bit

size information due to an inappropriate type of local variable to which

the i_size value is assigned.

This caused a large byte offset value due to underflow in the end address

calculation in the calling nilfs_find_entry(), resulting in memory access

that exceeds the folio/page size.

Fix this issue by changing the type of the local variable causing the bit

loss from "unsigned int" to "u64".

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 2.6.30, < 5.4.287 Affected

Frequently Asked Questions

What is CVE-2024-56619?

CVE-2024-56619 is a high-severity vulnerability affecting linux linux_kernel. It was published on December 27, 2024 and has a CVSS 3.1 base score of 7.8 (HIGH).

How severe is CVE-2024-56619?

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2024-56619?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-56619?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-56619 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.