PT-2024-36844 · Linux+2 · Linux Kernel+2
Published
2024-10-11
·
Updated
2025-05-26
·
CVE-2024-56540
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved, which could lead to a race condition, potentially causing undefined behavior and kernel crashes due to null pointer dereferences. The issue is related to the
accel/ivpu component, where the recovery invocation during probe and resume could trigger a recovery process. The ivpu send receive internal() function is now utilized by the D0i3 entry, DCT initialization, and HWS initialization functions, and these functions have been modified to return error codes gracefully rather than initiating recovery. The updated functions are invoked within ivpu probe() and ivpu resume(), ensuring that any errors encountered during these stages result in a proper teardown or shutdown sequence.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu