PT-2024-28084 · Linux+5 · Linux Kernel+5

Published

2024-06-21

·

Updated

2026-03-13

·

CVE-2024-38622

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description The issue is related to a callback function pointer check in the Linux kernel's drm/msm/dpu module. Specifically, in the dpu core irq callback handler() function, the callback function pointer is compared to NULL but then unconditionally called by this pointer. This bug has been fixed by adding a conditional return. The Linux Verification Center (linuxtesting.org) found this issue using SVACE.
Recommendations Update to Linux kernel version 6.6.37 or later to resolve the issue. As a temporary workaround, consider adding a conditional check for the callback function pointer before calling it to prevent potential crashes or exploits.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38622
ECHO-6AF8-77FE-4A6B
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1836
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7008-1
USN-7029-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu