PT-2024-32141 · Linux+6 · Linux Kernel+6

Julien Stephan

·

Published

2024-05-30

·

Updated

2026-05-26

·

CVE-2024-46715

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to missing checks on iio info's callback access in the Linux kernel. Some callbacks from the iio info structure are accessed without any check, leading to a kernel oops when a driver doesn't implement them and tries to access the corresponding sysfs entries. This results in a NULL pointer dereference at a virtual address. The call trace includes functions such as iio read channel info avail, dev attr show, sysfs kf seq show, seq read iter, vfs read, and ksys read.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Unchecked Return Value

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-55228
BDU:2025-04658
CVE-2024-46715
DLA-4008-1
DSA-5782-1
OPENSUSE-SU-2024_3551-1
OPENSUSE-SU-2024_3561-1
OPENSUSE-SU-2024_3564-1
OPENSUSE-SU-2024_3587-1
OPENSUSE-SU-2024_3592-1
SUSE-SU-2024:3551-1
SUSE-SU-2024:3553-1
SUSE-SU-2024:3559-1
SUSE-SU-2024:3561-1
SUSE-SU-2024:3564-1
SUSE-SU-2024:3566-1
SUSE-SU-2024:3569-1
SUSE-SU-2024:3587-1
SUSE-SU-2024:3591-1
SUSE-SU-2024:3592-1
SUSE-SU-2025:20073-1
SUSE-SU-2025:20077-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7196-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu