CVE-2024-56772: kunit: string-stream: Fix a UAF bug in kunit_init_suite()

Published Jan 8, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

kunit: string-stream: Fix a UAF bug in kunitinitsuite()

In kunitdebugfscreatesuite(), if allocstringstream() fails in the kunitsuiteforeachtestcase() loop, the "suite->log = stream" has assigned before, and the error path only free the suite->log's stream memory but not set it to NULL, so the later stringstreamclear() of suite->log in kunitinitsuite() will cause below UAF bug.

Set stream pointer to NULL after free to fix it.

Unable to handle kernel paging request at virtual address 006440150000030d Mem abort info: ESR = 0x0000000096000004 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault Data abort info: ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 CM = 0, WnR = 0, TnD = 0, TagAccess = 0 GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [006440150000030d] address between user and kernel address ranges Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP Dumping ftrace buffer: (ftrace buffer empty) Modules linked in: iiotestgts industrialiogtshelper cfg80211 rfkill ipv6 [last unloaded: iiotestgts] CPU: 5 UID: 0 PID: 6253 Comm: modprobe Tainted: G B W N 6.12.0-rc4+ #458 Tainted: [B]=BADPAGE, [W]=WARN, [N]=TEST Hardware name: linux,dummy-virt (DT) pstate: 40000005 (nZcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : stringstreamclear+0x54/0x1ac lr : stringstreamclear+0x1a8/0x1ac sp : ffffffc080b47410 x29: ffffffc080b47410 x28: 006440550000030d x27: ffffff80c96b5e98 x26: ffffff80c96b5e80 x25: ffffffe461b3f6c0 x24: 0000000000000003 x23: ffffff80c96b5e88 x22: 1ffffff019cdf4fc x21: dfffffc000000000 x20: ffffff80ce6fa7e0 x19: 032202a80000186d x18: 0000000000001840 x17: 0000000000000000 x16: 0000000000000000 x15: ffffffe45c355cb4 x14: ffffffe45c35589c x13: ffffffe45c03da78 x12: ffffffb810168e75 x11: 1ffffff810168e74 x10: ffffffb810168e74 x9 : dfffffc000000000 x8 : 0000000000000004 x7 : 0000000000000003 x6 : 0000000000000001 x5 : ffffffc080b473a0 x4 : 0000000000000000 x3 : 0000000000000000 x2 : 0000000000000001 x1 : ffffffe462fbf620 x0 : dfffffc000000000 Call trace: stringstreamclear+0x54/0x1ac kunittestsuitesinit+0x108/0x1d8 kunitexecruntests+0xb8/0x100 kunitmodulenotify+0x400/0x55c notifiercallchain+0xfc/0x3b4 blockingnotifiercallchain+0x68/0x9c doinitmodule+0x24c/0x5c8 loadmodule+0x4acc/0x4e90 initmodulefromfile+0xd4/0x128 idempotentinitmodule+0x2d4/0x57c arm64sysfinitmodule+0xac/0x100 invokesyscall+0x6c/0x258 el0svccommon.constprop.0+0x160/0x22c doel0svc+0x44/0x5c el0svc+0x48/0xb8 el0t64synchandler+0x13c/0x158 el0t64sync+0x190/0x194 Code: f9400753 d2dff800 f2fbffe0 d343fe7c (38e06b80) ---[ end trace 0000000000000000 ]--- Kernel panic - not syncing: Oops: Fatal exception

Other sources

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

Affected Software

2 affected componentsFixes available
Linux Linux kernel>=6.7<6.12.4
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1

Event History

Jan 8, 2025
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
Description
Mar 27, 2025
Data Sourced
via Launchpad·06:47 PM
Description
May 2, 2025
Data Sourced
via Ubuntu·06:55 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-56772?

CVE-2024-56772 has been rated as a moderate severity vulnerability affecting the Linux kernel.

2

How do I fix CVE-2024-56772?

To fix CVE-2024-56772, update the Linux kernel to version 6.12.5 or later.

3

What versions of the Linux kernel are affected by CVE-2024-56772?

CVE-2024-56772 affects the Linux kernel versions 6.7 to 6.12.4.

4

What type of vulnerability is CVE-2024-56772?

CVE-2024-56772 is a use-after-free (UAF) vulnerability in the Linux kernel.

5

Where does CVE-2024-56772 occur?

CVE-2024-56772 occurs in the kunit_debugfs_create_suite() function of the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203