PT-2024-10406 · Linux+5 · Linux Kernel+5

Tony Battersby

·

Published

2024-05-14

·

Updated

2025-02-03

·

CVE-2024-39296

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the bonding driver in the Linux kernel, specifically with the bonding init() and bonding exit() functions, which are associated with errors in resource management. The vulnerability can be exploited to cause a denial of service. The problem arises when "rmmod bonding" is executed, leading to an oops due to a removed check for bonding debug root == NULL in the debugfs remove() function. This can happen during module removal or if there is an error during module initialization. The vulnerability is caused by a race condition that can occur when multiple CPUs are involved in the process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00934
CVE-2024-39296
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1836
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7008-1
USN-7029-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu