PT-2024-36930 · Linux+3 · Linux Kernel+3

Manivannan Sadhasivam

·

Published

2024-11-20

·

Updated

2025-09-29

·

CVE-2024-56621

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability has been resolved in the Linux kernel. The issue is related to the scsi: ufs: core, where the RTC work is not cancelled during ufshcd remove(), leading to a NULL pointer dereference. This occurs because the RTC work accesses the ufshcd internal structures and should be cancelled when ufshcd is removed. The vulnerability can result in a kernel NULL pointer dereference at a virtual address.
Recommendations To resolve the issue, cancel the RTC work during ufshcd remove(), following the order in ufshcd init(). As a temporary workaround, consider disabling the ufshcd rtc work function until a patch is available. Restrict access to the ufshcd internal structures to minimize the risk of exploitation. Avoid triggering the RTC work after ufshcd remove() until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-17881
BDU:2025-15357
CVE-2024-56621
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Ubuntu