PT-2024-3398 · Linux+3 · Linux Kernel+3

Johan Hovold

·

Published

2024-02-23

·

Updated

2025-11-21

·

CVE-2024-26909

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A use-after-free issue has been identified in the Linux kernel, specifically in the pmic glink altmode driver. This issue arises due to a race condition where the dp-hpd bridge is registered before all resources have been acquired, allowing it to be deregistered on probe deferrals. As a result, when the display controller is initialized, it may trigger a use-after-free error when attaching bridges, potentially causing the display subsystem to fail to initialize or resulting in NULL-pointer dereferences. The issue has been observed in machines like the Lenovo ThinkPad X13s. The fix involves moving the bridge registration in the pmic glink altmode driver to after all resources have been looked up.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

NULL Pointer Dereference

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-40106
BDU:2024-03670
CVE-2024-26909
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse