CVE-2024-56699
Last modified
CVE-2024-56699 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix potential double remove of hotplug slot In commit 6ee600bfbe0f ("s390/pci: remove hotplug slot when releasing the device") the zpci_exit_slot() was moved from zpci_device_reserved() to zpci_release_device() with the intention of keeping the hotplug slot around until the device is actually removed. Now zpci_release_device() is only called once all references are dropped. Since the zPCI subsystem only drops its reference once the device is in the reserved state it follows that zpci_release_device() must only deal with devices in the reserved state. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix potential double remove of hotplug slot In commit 6ee600bfbe0f ("s390/pci: remove hotplug slot when releasing the device") the zpci_exit_slot() was moved from zpci_device_reserved() to zpci_release_device() with the intention of keeping the hotplug slot around until the device is actually removed. Now zpci_release_device() is only called once all references are dropped. Since the zPCI subsystem only drops its reference once the device is in the reserved state it follows that zpci_release_device() must only deal with devices in the reserved state. Despite that it contains code to tear down from both configured and standby state. For the standby case this already includes the removal of the hotplug slot so would cause a double removal if a device was ever removed in either configured or standby state. Instead of causing a potential double removal in a case that should never happen explicitly WARN_ON() if a device in non-reserved state is released and get rid of the dead code cases.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.9, < 6.11.11 |
| Linux | Linux Kernel | >= 6.12, < 6.12.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-56699?
How severe is CVE-2024-56699?
How do I fix CVE-2024-56699?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-56693In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-56694In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56695In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-56696In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56697In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56698In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-5670The web services of Softnext's products, Mail SQR Expert and…9.8
- CVE-2024-56700In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56701In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56702In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56703In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56704In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2024-56699?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
