CVE-2024-56675 is a use-after-free vulnerability in Linux kernel BPF tracing caused by mismatched RCU lifetime protections. Uprobes execute BPF programs through bpf_prog_run_array_uprobe() under tasks-trace-RCU protection, whereas attached non-sleepable BPF programs are freed through normal RCU by __bpf_prog_put_noref(). Completion of a normal RCU grace period does not guarantee completion of a tasks-trace-RCU grace period, allowing a bpf_prog to be freed while an uprobe execution still accesses it. The issue was introduced in Linux kernel 6.0 and can potentially cause memory disclosure, memory corruption, denial of service, or unauthorized code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel BPF use-after-free vulnerability caused by mismatched RCU synchronization when non-sleepable BPF programs are attached to uprobes. The fix waits for a tasks-trace-RCU grace period after removing a BPF program's attachment to a perf_event. The reference assigns a CVSS v3 score of 7.8, indicating a local attack requiring low privileges with potentially high confidentiality, integrity, and availability impacts. It recommends updating the affected Google COS kernel packages to version 18613.75.114 or later.
Use-after-free caused by mismatched BPF program and attachment RCU lifetimes.
Linux kernel BPF use-after-free vulnerability.
Linux kernel BPF use-after-free vulnerability involving mismatched RCU handling.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.