Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-56582

21
FAUCET Score

CVE-2024-56582 describes a use-after-free vulnerability in the Btrfs filesystem component of the Linux kernel. This flaw, specifically within the btrfs_encoded_read_endio() function, can lead to system instability or potential privilege escalation. It affects various Linux kernel versions. The vulnerability has a CVSS v3.1 score of 7.8 (High), indicating a significant risk. An attacker with local access (AV:L, PR:L) could exploit this with low attack complexity (AC:L) to achieve high confidentiality, integrity, and availability impacts (C:H, I:H, A:H). Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting a low profile in the threat landscape.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.18, < 6.1.124CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.70CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.12.4CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 47th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.64.2-9 on Azure Linux 3.0Fixed in: 6.6.76.1-1
microsoftpatch availablevia msrc
Product: 17476-17084Fixed in: 6.6.76.1-1
microsoftpatch availablevia msrc
Product: 17501-17084Fixed in: 6.6.76.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.76.1-1 on Azure Linux 3.0Fixed in: 6.6.76.1-1

Vendor Advisories (5)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2024-56582Moderate

kernel: btrfs: fix use-after-free in btrfs_encoded_read_endio()

Dec 27, 2024
microsoft2024-Dec/CVE-2024-56582Important

btrfs: fix use-after-free in btrfs_encoded_read_endio()

Dec 10, 2024

References

git.kernel.org / stable/c/05b36b04d74a517d6675bf2f90829ff1ac7e28dc
Patch
git.kernel.org / stable/c/6228f13f1996a4feb9b601d6644bf0bfe03671dd
Patch
git.kernel.org / stable/c/a40de0330af4fb7bc6b354250c24f294f8b826a0
Patch
git.kernel.org / stable/c/f8a5129e4a9fc3f6aa3f137513253b51b31b94d4
Patch
lists.debian.org / debian-lts-announce/2025/03/msg00001.html