PT-2024-36844 · Linux+2 · Linux Kernel+2

Published

2024-10-11

·

Updated

2025-05-26

·

CVE-2024-56540

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, which could lead to a race condition, potentially causing undefined behavior and kernel crashes due to null pointer dereferences. The issue is related to the accel/ivpu component, where the recovery invocation during probe and resume could trigger a recovery process. The ivpu send receive internal() function is now utilized by the D0i3 entry, DCT initialization, and HWS initialization functions, and these functions have been modified to return error codes gracefully rather than initiating recovery. The updated functions are invoked within ivpu probe() and ivpu resume(), ensuring that any errors encountered during these stages result in a proper teardown or shutdown sequence.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15956
CVE-2024-56540
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu