PT-2024-33888 · Linux+7 · Linux Kernel+7

Syzbot

·

Published

2024-10-21

·

Updated

2026-05-26

·

CVE-2024-50048

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.58
Description: A NULL pointer dereference issue in the Linux kernel's fbcon putcs function has been resolved. The issue was discovered by syzbot and can be triggered by calling ioctl(fd1, TIOCLINUX, &param) followed by ioctl(fd, FBIOPUT CON2FBMAP, &con2fb), causing the kernel to follow a different execution path and leading to a kernel panic. The vulnerable execution path includes the functions set con2fb map, con2fb init display, fbcon set disp, redraw screen, hide cursor, clear selection, highlight, invert screen, do update region, fbcon putcs, and ops->putcs. To prevent this, it is necessary to call set blitting type() within set con2fb map() to properly initialize ops->putcs.
Recommendations: To resolve the issue, update the Linux kernel to version 6.6.58 or later. As a temporary workaround, consider restricting access to the vulnerable ioctl functions until a patch is available. Avoid using the param struct with type 2 in the TIOCLINUX ioctl call until the issue is resolved.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-14268
ALT-PU-2024-14704
ALT-PU-2024-17211
ALT-PU-2025-12647
AZL-50791
AZL-50942
BDU:2025-07937
CVE-2024-50048
DLA-4008-1
MGASA-2024-0344
MGASA-2024-0345
OESA-2024-2522
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_3986-1
OPENSUSE-SU-2025:14705-1
SUSE-SU-2024:3983-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:3986-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7383-1
USN-7383-2
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7403-1
USN-7451-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu