PT-2024-32148 · Linux+5 · Linux Kernel+5

Leesoo Ahn

·

Published

2024-05-10

·

Updated

2025-09-29

·

CVE-2024-46721

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 6.8.0-24-generic #24 and earlier
Description A NULL pointer dereference vulnerability has been resolved in the Linux kernel. The issue occurs when the profile->parent->dents[AAFS PROF DIR] pointer is NULL, which can happen if its parent is made from create missing ancestors() and 'ent->old' is NULL in aa replace profiles(). This vulnerability can cause a kernel NULL pointer dereference.
Recommendations To resolve this issue, update the Linux kernel to a version later than 6.8.0-24-generic #24. As a temporary workaround, consider disabling the aafs create.constprop.0() function until a patch is available. Restrict access to the vulnerable aa replace profiles() function to minimize the risk of exploitation. Avoid using the profile->parent->dents[AAFS PROF DIR] pointer in the affected API endpoint until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-12535
ALT-PU-2024-12537
ALT-PU-2024-12541
ALT-PU-2024-12968
ALT-PU-2024-12970
ALT-PU-2024-13121
ALT-PU-2024-13166
ALT-PU-2024-13260
ALT-PU-2024-13979
ALT-PU-2024-14046
ALT-PU-2024-15824
AZL-49389
BDU:2025-01750
CVE-2024-46721
DLA-3912-1
DLA-4008-1
DSA-5782-1
OESA-2024-2216
OESA-2024-2217
OESA-2024-2218
OESA-2024-2219
OESA-2024-2220
OPENSUSE-SU-2024_3587-1
OPENSUSE-SU-2024_3592-1
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3986-1
SUSE-SU-2024:3559-1
SUSE-SU-2024:3566-1
SUSE-SU-2024:3569-1
SUSE-SU-2024:3587-1
SUSE-SU-2024:3591-1
SUSE-SU-2024:3592-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3986-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7088-1
USN-7088-2
USN-7088-3
USN-7088-4
USN-7088-5
USN-7100-1
USN-7100-2
USN-7119-1
USN-7123-1
USN-7144-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7194-1
USN-7196-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu