PT-2024-21571 · Linux+3 · Linux Kernel+3

Published

2024-02-28

·

Updated

2026-03-13

·

CVE-2024-26902

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.0-rc3+
Description The Linux kernel has a vulnerability that can cause a kernel panic when running the command 'perf record -e branches' on certain hardware, such as the Sophgo sg2042. This issue occurs due to a NULL pointer dereference in the pmu overflow handler. The problem arises when setting bits in the unsigned long overflowed ctrs using the expression (1 << idx) of type int, which is not desired. Instead, the BIT() function should be used.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, versions prior to 6.6.0-rc3+ are affected, so updating to 6.6.0-rc3+ or later will resolve the issue.
Note: The provided information does not specify the exact fixed version, but it implies that versions prior to 6.6.0-rc3+ are vulnerable. Therefore, updating to the latest available version of the Linux kernel is recommended to ensure the fix is included.

Exploit

Fix

NULL Pointer Dereference

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-14046
AZL-40076
AZL-40164
BDU:2025-02911
CVE-2024-26902
ECHO-B7A4-7F83-51E2

Affected Products

Alt Linux
Astra Linux
Debian
Linux Kernel