CVE-2024-56651 - CVE House
Back to Database
Status published Unknown CVE-2024-56651

can: hi311x: hi3110_can_ist(): fix potential use-after-free

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: can: hi311x: hi3110_can_ist(): fix potential use-after-free The commit a22bd630cfff ("can: hi311x: do not report txerr and rxerr during bus-off") removed the reporting of rxerr and txerr even in case of correct operation (i. e. not bus-off). The error count information added to the CAN frame after netif_rx() is a potential use after free, since there is no guarantee that the skb is in the same state. It might be freed or reused. Fix the issue by postponing the netif_rx() call in case of txerr and rxerr reporting.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-56651

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
a22bd630cfff496b270211745536e50e98eb3a45, 303733fdab728d34708014b3096dc69ebae6e531, 410054f1cf75378a6f009359e5952a240102a1a2, d20bf7e76136fd4c1e47502a1f5773f2290013ed, 22e382d47de09e865a9214cc5c9f99256e65deaa, dcfcd5fc999b1eb7946de1fd031bc3aaf224c5ae, 330b0ac34beec4fef8b002549af5bc6d0b6f0836, f3d865a6b791abbc874739ed702ae64ad2607511, 4.14.291, 4.19.256, 5.4.211, 5.10.137, 5.15.61, 5.18.18, 5.19.2, 6.0, 0, 6.1.120, 6.6.66, 6.12.5, 6.13

Timeline

Official Publish: December 27th, 2024
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.