PT-2024-36887 · Linux+2 · Linux Kernel+2

Published

2024-10-12

·

Updated

2025-05-26

·

CVE-2024-56580

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the configuration of CAMSS power domains in the Linux kernel. There is a chance to encounter runtime issues because the dev pm domain detach() function is unexpectedly called with a NULL or error pointer on the error path. This can be reproduced by probing the CAMSS driver before registering the CAMSS power domains, for instance, if a platform CAMCC driver is not built. A warning backtrace example shows a kernel NULL pointer dereference at a virtual address.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15356
CVE-2024-56580
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu