PT-2024-34107 · Linux+2 · Linux Kernel+2

Parthiban N

·

Published

2024-11-04

·

Updated

2025-02-28

·

CVE-2024-50281

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A NULL pointer dereference issue has been identified in the Linux kernel, specifically in the KEYS: trusted: dcp component. This issue occurs when sealing or unsealing a key blob, as the system does not wait for the AEAD cipher operation to finish before resuming the seal and unseal calls. Under heavy system load, this can result in the buffer being removed from the stack before the cipher operation is complete, leading to NULL pointer dereference errors in the DCP driver during blob creation.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14146
CVE-2024-50281
USN-7276-1
USN-7277-1
USN-7310-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu