{"id":"DEBIAN-CVE-2024-56772","details":"In the Linux kernel, the following vulnerability has been resolved:  kunit: string-stream: Fix a UAF bug in kunit_init_suite()  In kunit_debugfs_create_suite(), if alloc_string_stream() fails in the kunit_suite_for_each_test_case() loop, the \"suite-\u003elog = stream\" has assigned before, and the error path only free the suite-\u003elog's stream memory but not set it to NULL, so the later string_stream_clear() of suite-\u003elog in kunit_init_suite() will cause below UAF bug.  Set stream pointer to NULL after free to fix it.  \tUnable to handle kernel paging request at virtual address 006440150000030d \tMem abort info: \t  ESR = 0x0000000096000004 \t  EC = 0x25: DABT (current EL), IL = 32 bits \t  SET = 0, FnV = 0 \t  EA = 0, S1PTW = 0 \t  FSC = 0x04: level 0 translation fault \tData abort info: \t  ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 \t  CM = 0, WnR = 0, TnD = 0, TagAccess = 0 \t  GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 \t[006440150000030d] address between user and kernel address ranges \tInternal error: Oops: 0000000096000004 [#1] PREEMPT SMP \tDumping ftrace buffer: \t   (ftrace buffer empty) \tModules linked in: iio_test_gts industrialio_gts_helper cfg80211 rfkill ipv6 [last unloaded: iio_test_gts] \tCPU: 5 UID: 0 PID: 6253 Comm: modprobe Tainted: G    B   W        N 6.12.0-rc4+ #458 \tTainted: [B]=BAD_PAGE, [W]=WARN, [N]=TEST \tHardware name: linux,dummy-virt (DT) \tpstate: 40000005 (nZcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) \tpc : string_stream_clear+0x54/0x1ac \tlr : string_stream_clear+0x1a8/0x1ac \tsp : ffffffc080b47410 \tx29: ffffffc080b47410 x28: 006440550000030d x27: ffffff80c96b5e98 \tx26: ffffff80c96b5e80 x25: ffffffe461b3f6c0 x24: 0000000000000003 \tx23: ffffff80c96b5e88 x22: 1ffffff019cdf4fc x21: dfffffc000000000 \tx20: ffffff80ce6fa7e0 x19: 032202a80000186d x18: 0000000000001840 \tx17: 0000000000000000 x16: 0000000000000000 x15: ffffffe45c355cb4 \tx14: ffffffe45c35589c x13: ffffffe45c03da78 x12: ffffffb810168e75 \tx11: 1ffffff810168e74 x10: ffffffb810168e74 x9 : dfffffc000000000 \tx8 : 0000000000000004 x7 : 0000000000000003 x6 : 0000000000000001 \tx5 : ffffffc080b473a0 x4 : 0000000000000000 x3 : 0000000000000000 \tx2 : 0000000000000001 x1 : ffffffe462fbf620 x0 : dfffffc000000000 \tCall trace: \t string_stream_clear+0x54/0x1ac \t __kunit_test_suites_init+0x108/0x1d8 \t kunit_exec_run_tests+0xb8/0x100 \t kunit_module_notify+0x400/0x55c \t notifier_call_chain+0xfc/0x3b4 \t blocking_notifier_call_chain+0x68/0x9c \t do_init_module+0x24c/0x5c8 \t load_module+0x4acc/0x4e90 \t init_module_from_file+0xd4/0x128 \t idempotent_init_module+0x2d4/0x57c \t __arm64_sys_finit_module+0xac/0x100 \t invoke_syscall+0x6c/0x258 \t el0_svc_common.constprop.0+0x160/0x22c \t do_el0_svc+0x44/0x5c \t el0_svc+0x48/0xb8 \t el0t_64_sync_handler+0x13c/0x158 \t el0t_64_sync+0x190/0x194 \tCode: f9400753 d2dff800 f2fbffe0 d343fe7c (38e06b80) \t---[ end trace 0000000000000000 ]--- \tKernel panic - not syncing: Oops: Fatal exception","modified":"2026-09-15T09:03:16.171216806Z","published":"2025-01-08T18:15:17.897Z","upstream":["CVE-2024-56772"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-56772"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56772.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56772.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}