PT-2024-21589 · Linux+3 · Linux Kernel+3

William Wortel

·

Published

2024-03-25

·

Updated

2024-07-04

·

CVE-2024-26942

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL dereference bug was introduced in the at803x driver when it was reworked and split. This bug causes the priv variable to be referenced before it is allocated, leading to a kernel panic when trying to write to the is 1000basex and is fiber variables in the case of at8031. The issue is resolved by correctly setting the priv local variable only after at803x probe is called and actually allocates priv in the phydev struct.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02916
CVE-2024-26942
USN-6816-1
USN-6817-1
USN-6817-2
USN-6817-3
USN-6878-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Ubuntu