{"id":"CVE-2024-56720","summary":"bpf, sockmap: Several fixes to bpf_msg_pop_data","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Several fixes to bpf_msg_pop_data\n\nSeveral fixes to bpf_msg_pop_data,\n1. In sk_msg_shift_left, we should put_page\n2. if (len == 0), return early is better\n3. pop the entire sk_msg (last == msg-\u003esg.size) should be supported\n4. Fix for the value of variable \"a\"\n5. In sk_msg_shift_left, after shifting, i has already pointed to the next\nelement. Addtional sk_msg_iter_var_next may result in BUG.","modified":"2026-04-02T12:25:10.950404Z","published":"2024-12-29T11:29:58.345Z","related":["SUSE-SU-2025:0784-1","SUSE-SU-2025:0847-1","SUSE-SU-2025:0856-1","SUSE-SU-2025:0955-1","SUSE-SU-2025:20190-1","SUSE-SU-2025:20192-1","SUSE-SU-2025:20260-1","SUSE-SU-2025:20270-1","USN-7276-1","USN-7277-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56720.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/275a9f3ef8fabb0cb282a62b9e164dedba7284c5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5d609ba262475db450ba69b8e8a557bd768ac07a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/785180bed9879680d8e5c5e1b54c8ae8d948f4c8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/98c7ea7d11f2588e8197db042e0291e4ac8f8346"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d26d977633d1d0b8bf9407278189bd0a8d973323"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d3f5763b3062514a234114e97bbde74d8d702449"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e1f54c61c4c9a5244eb8159dce60d248f7d97b32"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f58d3aa457e77a3d9b3df2ab081dcf9950f6029f"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56720.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56720"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"7246d8ed4dcce23f7509949a77be15fa9f0e3d28"},{"fixed":"d3f5763b3062514a234114e97bbde74d8d702449"},{"fixed":"d26d977633d1d0b8bf9407278189bd0a8d973323"},{"fixed":"e1f54c61c4c9a5244eb8159dce60d248f7d97b32"},{"fixed":"f58d3aa457e77a3d9b3df2ab081dcf9950f6029f"},{"fixed":"98c7ea7d11f2588e8197db042e0291e4ac8f8346"},{"fixed":"785180bed9879680d8e5c5e1b54c8ae8d948f4c8"},{"fixed":"275a9f3ef8fabb0cb282a62b9e164dedba7284c5"},{"fixed":"5d609ba262475db450ba69b8e8a557bd768ac07a"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-56720.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}