PT-2024-28506 · Linux+6 · Linux Kernel+6

Konrad Dybcio

·

Published

2024-03-09

·

Updated

2025-09-29

·

CVE-2024-39466

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description The issue is related to the thermal drivers in the Linux kernel, specifically the qcom/lmh driver. A check for SCM availability was not performed, leading to possible null pointer dereferences. This issue has been resolved by adding the necessary check.
Recommendations Update to Linux kernel version 6.6.37 or later to resolve the issue. As a temporary workaround, consider disabling the thermal drivers until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the affected driver until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-11524
ALT-PU-2024-13979
ALT-PU-2024-14046
BDU:2025-03033
CVE-2024-39466
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1836
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7007-1
USN-7007-2
USN-7007-3
USN-7008-1
USN-7009-1
USN-7009-2
USN-7019-1
USN-7029-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu