PT-2024-3398 · Linux+3 · Linux Kernel+3
Johan Hovold
·
Published
2024-02-23
·
Updated
2025-11-21
·
CVE-2024-26909
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A use-after-free issue has been identified in the Linux kernel, specifically in the pmic glink altmode driver. This issue arises due to a race condition where the dp-hpd bridge is registered before all resources have been acquired, allowing it to be deregistered on probe deferrals. As a result, when the display controller is initialized, it may trigger a use-after-free error when attaching bridges, potentially causing the display subsystem to fail to initialize or resulting in NULL-pointer dereferences. The issue has been observed in machines like the Lenovo ThinkPad X13s. The fix involves moving the bridge registration in the pmic glink altmode driver to after all resources have been looked up.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use After Free
NULL Pointer Dereference
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse