efi/libstub: Free correct pointer on failure
Published Dec 27, 2024
7.0
HIGHCVSS 3.1
EPSS 0.23%
Description
cmdline_ptr is an out parameter, which is not allocated by the function itself, and likely points into the caller's stack.
cmdline refers to the pool allocation that should be freed when cleaning up after a failure, so pass this instead to free_pool().
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 6.2
Unaffected
- ≥ 0, < 6.2
- ≥ 6.12.4, ≤ 6.12.*
- 6.13
- ≥ 6.6.64, ≤ 6.6.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 6.2 · < 6.6.64
- ≥ 6.7 · < 6.12.4
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2024-56573 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2334465 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-53221 Advisory
- https://git.kernel.org/stable/c/06d39d79cbd5a91a33707951ebf2512d0e759847 Patch
- https://git.kernel.org/stable/c/d173aee5709bd0994d216d60589ec67f8b11376a Patch
- https://git.kernel.org/stable/c/eaafbcf0a5782ae412ca7de12ef83fc48ccea4cf Patch
- https://lore.kernel.org/linux-cve-announce/2024122717-CVE-2024-56573-f5d2@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-56573
- https://www.cve.org/CVERecord?id=CVE-2024-56573
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data