PT-2024-33941 · Linux+4 · Linux Kernel+4

Valdikss

·

Published

2024-10-09

·

Updated

2025-09-29

·

CVE-2024-50109

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A null pointer dereference issue in the Linux kernel has been identified. The problem occurs in the raid10 size() function when mddev->private is still NULL after raid10 set queue limits() succeeds, and subsequent procedures fail, causing raid10 run() to return zero. This issue is resolved by only overwriting the return value if raid10 set queue limits() fails.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17211
BDU:2025-13978
CVE-2024-50109
INFSA-2025_6966
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2025:14705-1
RHSA-2025:6966
RHSA-2025_6966
USN-7276-1
USN-7277-1
USN-7310-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Red Hat
Ubuntu