PT-2024-35635 · Linux+4 · Linux Kernel+4

Published

2024-10-17

·

Updated

2025-10-03

·

CVE-2024-53188

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, specifically in the wifi: ath12k module. The issue occurs when there is an error during firmware initialization, causing the ath12k dp cc cleanup function to be called to release resources. However, this release is done again when the device is unbound, resulting in a kernel NULL pointer dereference. The problem is always reproducible from a virtual machine due to failing MSI addressing initialization.
Recommendations To fix the issue, set the released structure to NULL in the ath12k dp cc cleanup function at the end. This will prevent the kernel NULL pointer dereference and resolve the vulnerability.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17893
ALT-PU-2025-12647
AZL-55631
BDU:2025-07872
CVE-2024-53188
OESA-2025-1594
OESA-2025-1595
OPENSUSE-SU-2025_0117-1
OPENSUSE-SU-2025_0153-1
OPENSUSE-SU-2025_0154-1
SUSE-SU-2025:0117-1
SUSE-SU-2025:0153-1
SUSE-SU-2025:0154-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu