PT-2024-10406 · Linux+5 · Linux Kernel+5
Tony Battersby
·
Published
2024-05-14
·
Updated
2025-02-03
·
CVE-2024-39296
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the bonding driver in the Linux kernel, specifically with the
bonding init() and bonding exit() functions, which are associated with errors in resource management. The vulnerability can be exploited to cause a denial of service. The problem arises when "rmmod bonding" is executed, leading to an oops due to a removed check for bonding debug root == NULL in the debugfs remove() function. This can happen during module removal or if there is an error during module initialization. The vulnerability is caused by a race condition that can occur when multiple CPUs are involved in the process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu