PT-2024-27189 · Linux+4 · Linux Kernel+4

Jerry Snitselaar

·

Published

2024-05-09

·

Updated

2025-09-29

·

CVE-2024-36884

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.9.0-0.rc7.58.eln136.aarch64
Description The vulnerability is related to the iommu/arm-smmu component in the Linux kernel. It was caused by a function pointer indirection issue in the nvidia smmu context fault() function, which is also installed as an IRQ function. The 'void *' was changed to a struct arm smmu domain, but since the iommu domain is embedded at a non-zero offset, this causes nvidia smmu context fault() to miscompute the offset. The issue results in a kernel NULL pointer dereference at a virtual address.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2025-03054
CVE-2024-36884
INFSA-2024_9315
OESA-2024-2325
RHSA-2024:9315
RHSA-2024_9315
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Hat
Ubuntu