CVE-2024-56582 describes a use-after-free vulnerability in the Btrfs filesystem component of the Linux kernel. This flaw, specifically within the btrfs_encoded_read_endio() function, can lead to system instability or potential privilege escalation. It affects various Linux kernel versions. The vulnerability has a CVSS v3.1 score of 7.8 (High), indicating a significant risk. An attacker with local access (AV:L, PR:L) could exploit this with low attack complexity (AC:L) to achieve high confidentiality, integrity, and availability impacts (C:H, I:H, A:H). Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting a low profile in the threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.18, < 6.1.124CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.70CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025kernel: btrfs: fix use-after-free in btrfs_encoded_read_endio()
Dec 27, 2024btrfs: fix use-after-free in btrfs_encoded_read_endio()
Dec 10, 2024