PT-2024-10323 · Linux+2 · Linux Kernel+2

Published

2024-09-02

·

Updated

2025-02-28

·

CVE-2024-47694

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a null pointer dereference in the mlx5r umr resource cleanup() function of the Linux kernel's Infiniband driver. This can lead to a denial of service. The problem arises when the pd allocation is moved from mlx5r umr resource cleanup() to mlx5r umr cleanup(), causing a panic if the pd pointer is null. The error occurs during the error flow of the driver initialization. Technical details include the ib dealloc pd user() function and the mlx5r umr cleanup() function being involved in the issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00775
CVE-2024-47694
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2025:14705-1
USN-7276-1
USN-7277-1
USN-7310-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu