PT-2024-34072 · Linux+4 · Linux Kernel+4

Johan Hovold

·

Published

2024-09-11

·

Updated

2025-10-03

·

CVE-2024-50240

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.61
Description: A vulnerability in the Linux kernel has been resolved, specifically in the phy: qcom: qmp-usb module. The issue was caused by a commit that removed the initialisation of the platform device driver data, despite it still being used in the runtime PM callbacks. This led to a NULL-pointer dereference on runtime suspend. The vulnerability is resolved by restoring the driver data initialisation at probe. It is noted that runtime PM is not commonly used and needs to be enabled manually through sysfs with this driver.
Recommendations: For Linux kernel versions prior to 6.6.61, update to version 6.6.61 or later to resolve the issue. As a temporary workaround, consider disabling runtime PM through sysfs to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17211
ALT-PU-2024-17891
ALT-PU-2025-12647
AZL-53166
BDU:2025-07898
CVE-2024-50240
MGASA-2024-0368
MGASA-2024-0369
OESA-2025-1097
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2025:14705-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu