CVE-2024-56751: ipv6: release nexthop on device removal

Published Dec 29, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ipv6: release nexthop on device removal

The CI is hitting some aperiodic hangup at device removal time in the pmtu.sh self-test:

unregisternetdevice: waiting for vethA-R1 to become free. Usage count = 6 reftracker: vethA-R1@ffff888013df15d8 has 1/5 users at dstinit+0x84/0x4a0 dstalloc+0x97/0x150 ip6dstalloc+0x23/0x90 ip6rtpcpualloc+0x1e6/0x520 ip6polroute+0x56f/0x840 fib6rulelookup+0x334/0x630 ip6routeoutputflags+0x259/0x480 ip6dstlookuptail.constprop.0+0x5c2/0x940 ip6dstlookupflow+0x88/0x190 udptunnel6dstlookup+0x2a7/0x4c0 vxlanxmitone+0xbde/0x4a50 [vxlan] vxlanxmit+0x9ad/0xf20 [vxlan] devhardstartxmit+0x10e/0x360 devqueuexmit+0xf95/0x18c0 arpsolicit+0x4a2/0xe00 neighprobe+0xaa/0xf0

While the first suspect is the dstcache, explicitly tracking the dst owing the last device reference via probes proved such dst is held by the nexthop in the originating fib6info.

Similar to commit f5b51fe804ec ("ipv6: route: purge exception on removal"), we need to explicitly release the originating fib info when disconnecting a to-be-removed device from a live ipv6 dst: move the fib6info cleanup into ip6dstifdown().

Tested running:

./pmtu.sh cleanupipv6exception

in a tight loop for more than 400 iterations with no spat, running an unpatched kernel I observed a splat every ~10 iterations.

Other sources

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

Affected Software

10 affected componentsFixes available
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1
debian/linux-6.1
6.1.129-1~deb11u1
Linux Linux kernel>=5.3<6.1.120
Linux Linux kernel>=6.2<6.6.64
Linux Linux kernel>=6.7<6.11.11
Linux Linux kernel>=6.12<6.12.2
Microsoft azl3 kernel 6.6.64.2-1
Microsoft cbl2 kernel 5.15.182.1-1
Microsoft azl3 kernel 6.6.57.1-7
Microsoft cbl2 kernel 5.15.182.1-1

Event History

Dec 29, 2024
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
Description
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityAffected Software
Jan 29, 2025
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Updated
via Microsoft·08:00 AM
Description
Apr 17, 2025
Data Sourced
via Launchpad·01:14 AM
Description
May 7, 2025
Data Sourced
via Ubuntu·01:14 AM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-56751?

CVE-2024-56751 has been classified with a severity level that indicates it could lead to potential kernel hangs during device removals.

2

How do I fix CVE-2024-56751?

To fix CVE-2024-56751, update your Linux kernel to a version that includes the resolution for this vulnerability.

3

What versions of the Linux kernel are affected by CVE-2024-56751?

CVE-2024-56751 affects Linux kernel versions from 5.3 up to 6.1.120 and from 6.2 up to 6.6.64, as well as several other specified version ranges.

4

What type of vulnerability is CVE-2024-56751?

CVE-2024-56751 is a vulnerability tied to the IPv6 handling within the Linux kernel, specifically concerning nexthop release on device removal.

5

Are there any known exploits for CVE-2024-56751?

As of now, there are no publicly disclosed exploits specifically targeting CVE-2024-56751.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203