PT-2024-28094 · Linux+4 · Linux Kernel+4

Mikhail Lobanov

·

Published

2024-03-25

·

Updated

2025-01-13

·

CVE-2024-38637

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns a vulnerability in the Linux kernel, specifically in the greybus: lights component. When a channel for a given node is not found, the function get channel from mode returns null. However, the return pointer is not validated before use in two places, potentially leading to issues. This was originally reported by the Linux Verification Center with SVACE.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04182
CVE-2024-38637
DLA-3840-1
DSA-5730-1
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1835
OESA-2024-1836
OESA-2024-1838
OESA-2024-1839
USN-6951-1
USN-6951-2
USN-6951-3
USN-6951-4
USN-6953-1
USN-6979-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7007-1
USN-7007-2
USN-7007-3
USN-7008-1
USN-7009-1
USN-7009-2
USN-7019-1
USN-7029-1
USN-7121-1
USN-7121-2
USN-7121-3

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu