PT-2024-26849 · Linux+5 · Linux Kernel+5

Published

2024-05-30

·

Updated

2026-05-26

·

CVE-2024-36021

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises when the devlink reload process accesses hardware resources during pf initialization, but the register operation is done before the hardware is initialized, potentially leading to a kernel crash. This is resolved by taking devl lock during initialization.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Initialization

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

BDU:2025-13365
CVE-2024-36021
OESA-2024-1706
OESA-2025-1078
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
USN-6893-1
USN-6893-2
USN-6893-3
USN-6918-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu