PT-2024-35578 · Linux+8 · Linux Kernel+8

Jinjiang Tu

·

Published

2024-11-13

·

Updated

2025-10-03

·

CVE-2024-53113

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.65
Description A NULL pointer dereference issue was found in the Linux kernel, specifically in the alloc pages bulk noprof() function. This issue occurs when a task is migrated between cpusets, causing the ac->preferred zoneref->zone pointer to become NULL. The for each zone zonelist nodemask() function finds an allowable zone and calls zonelist node idx(ac.preferred zoneref), leading to a NULL pointer dereference. The issue is fixed by checking for a NULL pointer in the alloc pages noprof() function.
Recommendations To fix this issue, update to Linux kernel version 6.6.65 or later. As a temporary workaround, consider disabling the alloc pages bulk noprof() function until a patch is available. Restrict access to the vulnerable zonelist node idx() function to minimize the risk of exploitation. Avoid using the ac->preferred zoneref->zone pointer in the affected alloc pages bulk noprof() function until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:2627
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALSA-2025_2627
ALT-PU-2024-16040
ALT-PU-2024-17211
ALT-PU-2024-17888
ALT-PU-2025-12647
AZL-54117
AZL-54188
BDU:2025-03317
CVE-2024-53113
DLA-4008-1
INFSA-2025_2627
MGASA-2024-0392
MGASA-2024-0393
OESA-2025-1093
OESA-2025-1097
OPENSUSE-SU-2025_0117-1
OPENSUSE-SU-2025_0153-1
OPENSUSE-SU-2025_0154-1
OPENSUSE-SU-2025_0201-1
OPENSUSE-SU-2025_0229-1
RHSA-2025:1253
RHSA-2025:1254
RHSA-2025:1268
RHSA-2025:1269
RHSA-2025:1658
RHSA-2025:2627
RHSA-2025_2627
SUSE-SU-2025:0117-1
SUSE-SU-2025:0153-1
SUSE-SU-2025:0154-1
SUSE-SU-2025:0201-1
SUSE-SU-2025:0201-2
SUSE-SU-2025:0229-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0201-1
SUSE-SU-2025_0201-2
USN-7276-1
USN-7277-1
USN-7310-1
USN-7387-1
USN-7387-2
USN-7387-3
USN-7388-1
USN-7389-1
USN-7390-1
USN-7407-1
USN-7421-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7458-1
USN-7459-1
USN-7459-2
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu