PT-2024-29772 · Linux+3 · Linux Kernel+3

Published

2024-04-17

·

Updated

2024-12-12

·

CVE-2024-42146

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the lack of outer runtime PM protection in the Linux kernel, specifically in the drm/xe module. Any kunit doing memory access should have its own runtime pm outer references since they don't use the standard driver API entries. The vulnerability was found by pre-merge CI on adding WARN calls for unprotected inner callers. The warning message indicates a missing outer runtime PM protection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02978
CVE-2024-42146
USN-7089-1
USN-7089-2
USN-7089-3
USN-7089-4
USN-7089-5
USN-7089-6
USN-7089-7
USN-7090-1
USN-7095-1
USN-7156-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Ubuntu