PT-2024-32141 · Linux+6 · Linux Kernel+6
Julien Stephan
·
Published
2024-05-30
·
Updated
2026-05-26
·
CVE-2024-46715
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to missing checks on
iio info's callback access in the Linux kernel. Some callbacks from the iio info structure are accessed without any check, leading to a kernel oops when a driver doesn't implement them and tries to access the corresponding sysfs entries. This results in a NULL pointer dereference at a virtual address. The call trace includes functions such as iio read channel info avail, dev attr show, sysfs kf seq show, seq read iter, vfs read, and ksys read.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Unchecked Return Value
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu