CVE-2024-56564
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-56564 addresses a reference leak vulnerability in the Linux kernel's Ceph filesystem implementation. The issue was discovered in the cephmdsauthmatch() function, where a redundant getcurrent_cred() call resulted in an unnecessary credential reference being taken (Kernel Git).

Technical details

The vulnerability stems from a redundant credential pointer acquisition in the cephmdsauthmatch() function. The function was making an unnecessary getcurrentcred() call despite cephmdscheckaccess() already having obtained the required credential pointer. This implementation resulted in taking an additional, unneeded credential reference (Kernel Git).

Impact

The vulnerability causes a reference leak in the Linux kernel's Ceph filesystem implementation, which could potentially lead to resource management issues over time (NVD).

Mitigation and workarounds

The vulnerability has been patched by modifying the cephmdsauthmatch() function to accept the credential pointer as a parameter instead of calling getcurrent_cred(). This fix eliminates the redundant credential reference acquisition and resolves the reference leak (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management