CVE-2024-56662: Linux Kernel

Medium severity, CVSS 6.0. EPSS: 0.6% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot with KASAN: BUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/ core.c:416 [inline] BUG: KASAN: vmalloc-out-of-bounds in acpi_nfit_ctl+0x20e8/0x24a0 drivers/acpi/nfit/core.c:459 The issue occurs in cmd_to_func when the call_pkg->nd_reserved2 array is accessed without verifying that call_pkg points to a buffer that is appropriately sized as a struct nd_cmd_pkg. This can lead to out-of-bounds access and undefined behavior if the buffer does not have sufficient space. To address this, a check was added in acpi_nfit_ctl() to ensure that buf is not NULL and that buf_len is less than sizeof(*call_pkg) before accessing it. This ensures safe access to the members of call_pkg, including the nd_reserved2 array.

Affected products

  • Linux Linux Kernel: from 4.14.176, before 4.15 (fixed in 4.15); from 4.19.31, before 4.20 (fixed in 4.20); from 5.0.4, before 5.10.232 (fixed in 5.10.232); from 5.11, before 5.15.175 (fixed in 5.15.175); from 5.16, before 6.1.121 (fixed in 6.1.121); from 6.2, before 6.6.67 (fixed in 6.6.67); …

Published 2024-12-27. Last modified 2026-08-04.