PT-2024-35528 · Linux+8 · Linux Kernel+8

Published

2024-11-04

·

Updated

2026-04-20

·

CVE-2024-53064

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, specifically in the idpf vc core init error path. When the platform running the device control plane is rebooted, the driver releases all resources and waits for the reset to complete. If the device control plane is not yet started after the reset, the driver times out on the virtchnl message and retries to establish the mailbox, leading to a null-ptr-deref due to accessing the released control queue. The issue arises from the mailbox being deinitialized while the mailbox workqueue is still alive and polling for the mailbox message.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:9580
ALSA-2025:9581
ALSA-2025_16880
ALT-PU-2024-17211
BDU:2025-15032
CESA-2025_9580
CESA-2025_9581
CVE-2024-53064
INFSA-2025_9580
INFSA-2025_9581
OPENSUSE-SU-2025_0117-1
OPENSUSE-SU-2025_0153-1
OPENSUSE-SU-2025_0154-1
OPENSUSE-SU-2025_0201-1
OPENSUSE-SU-2025_0229-1
OPENSUSE-SU-2025_1195-1
RHSA-2025:9580
RHSA-2025:9581
RHSA-2025_9580
RHSA-2025_9581
SUSE-SU-2025:0117-1
SUSE-SU-2025:0153-1
SUSE-SU-2025:0154-1
SUSE-SU-2025:0201-1
SUSE-SU-2025:0201-2
SUSE-SU-2025:0229-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1195-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0201-1
SUSE-SU-2025_0201-2
SUSE-SU-2025_1195-1
USN-7276-1
USN-7277-1
USN-7291-1
USN-7304-1
USN-7310-1
USN-7326-1
USN-7329-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu