CVE-2024-56690: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY Since commit 8f4f68e788c3 ("crypto: pcrypt - Fix hungtask for PADATA_RESET"), the pcrypt encryption and decryption operations return -EAGAIN when the CPU goes online or offline. In alg_test(), a WARN is generated when pcrypt_aead_decrypt() or pcrypt_aead_encrypt() returns -EAGAIN, the unnecessary panic will occur when panic_on_warn set 1. Fix this issue by calling crypto layer directly without parallelization in that case.

Affected products

  • Linux Linux Kernel: from 4.14.331, before 4.15 (fixed in 4.15); from 4.19.300, before 4.19.325 (fixed in 4.19.325); from 5.4.262, before 5.4.287 (fixed in 5.4.287); from 5.10.202, before 5.10.231 (fixed in 5.10.231); from 5.15.140, before 5.15.174 (fixed in 5.15.174); from 6.1.64, before 6.1.120 (fixed in 6.1.120); …

Published 2024-12-28. Last modified 2026-06-17.