PT-2024-26844 · Linux+9 · Linux Kernel+9

Published

2024-04-22

·

Updated

2025-09-29

·

CVE-2024-36007

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description The Linux kernel has a vulnerability in the mlxsw spectrum acl tcam module. The rehash delayed work migrates filters from one region to another by iterating over all chunks and filters. When the work runs out of credits, it stores the current chunk and entry as markers, but upon error, the chunk marker is reset to NULL without resetting the entry markers. This can lead to migration being resumed from an entry that does not belong to the chunk being migrated, resulting in warnings. The fix involves creating a helper to reset all markers and calling it from all places that currently only reset the chunk marker.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.37 or later. If updating is not possible, consider disabling the mlxsw spectrum acl tcam module as a temporary workaround to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4211
ALSA-2024:4352
ALSA-2025_16880
BDU:2025-03067
CESA-2024_4211
CESA-2024_4352
CVE-2024-36007
DLA-3842-1
INFSA-2024_4211
INFSA-2024_4352
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1694
OESA-2024-2295
RHSA-2024:4211
RHSA-2024:4352
RHSA-2024_4211
RHSA-2024_4352
RLSA-2024:4211
RLSA-2024:4352
RXSA-2024:4211
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6919-1
USN-6927-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1
USN-7019-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu