PT-2024-27193 · Linux+6 · Linux Kernel+6

Badhri Jagan Sridharan

·

Published

2024-04-27

·

Updated

2025-09-29

·

CVE-2024-36893

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises from the typec register partner() function not guaranteeing partner registration to always succeed. In the event of failure, port->partner is set to the error value or NULL. Given that port->partner validity is not checked, this results in a crash due to a kernel NULL pointer dereference. The crash occurs at virtual address xx, with a call trace involving run state machine(), tcpm state machine work(), kthread worker fn(), kthread(), and ret from fork(). To prevent the crash, it is necessary to check for port->partner validity before dereferencing it in all the call sites.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-11524
ALT-PU-2024-13979
ALT-PU-2024-14046
ALT-PU-2024-9127
AZL-42465
AZL-42496
BDU:2025-02945
CVE-2024-36893
MGASA-2024-0263
MGASA-2024-0266
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1
USN-7166-1
USN-7166-2
USN-7166-3
USN-7166-4
USN-7186-1
USN-7186-2
USN-7194-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu