CVE-2024-56675 is a use-after-free flaw in Linux kernel eBPF tracing introduced in kernel 6.0. Non-sleepable BPF programs attached to uprobes could be freed after a normal RCU grace period while uprobe execution still accessed them under tasks-trace-RCU protection, creating an unsafe lifetime mismatch. The upstream fix waits for a tasks-trace-RCU grace period after removing the BPF attachment from its perf_event; fixed stable releases include 6.1.121, 6.6.67, 6.12.6, and 6.13-rc3.
Red Hat rated the issue Moderate (CVSS 6.7) because default RHEL configurations disable unprivileged eBPF, requiring CAP_SYS_ADMIN or root privileges to exploit it. Fixes are available for RHEL 9 and RHEL 10 through RHSA-2025:20518 and RHSA-2025:20095, respectively; RHEL 9 kernel-rt remains affected, while RHEL 6, RHEL 8, and RHEL 8 kernel-rt are not affected. Organizations should deploy the applicable kernel update, with particular attention to systems where privileged users can load or attach eBPF programs.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:20095 for RHEL 10 and RHSA-2025:20518 for RHEL 9 to address CVE-2024-56675. RHEL 9 kernel-rt remained listed as affected.
Linux kernel fixes were made available in versions 6.1.121, 6.6.67, 6.12.6, and 6.13-rc3. The remediation explicitly waits for a tasks-trace-RCU grace period after removing a BPF program attachment from a perf event.
The Linux kernel CVE team assigned CVE-2024-56675 to the BPF tracing use-after-free issue in kernel/trace/bpf_trace.c. The flaw can allow a BPF program freed after a normal RCU grace period to remain accessible on an uprobe path protected by tasks-trace-RCU.
A change in Linux kernel 6.0 introduced mismatched normal-RCU and tasks-trace-RCU lifetime handling for BPF programs attached to uprobes, creating a potential use-after-free condition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.