PT-2024-4110 · Linux+6 · Linux Kernel+6

Syzbot

·

Published

2024-04-08

·

Updated

2025-09-29

·

CVE-2024-36938

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description The issue is related to a NULL pointer dereference in the sk psock skb ingress enqueue() function, which can cause a data-race. This vulnerability was reported by syzbot and is related to the sk psock drop() and sk psock skb ingress enqueue() functions. The sk psock verdict data ready() function is also affected. To avoid errors, the sk callback lock read lock should be used to protect the saved data ready variable.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.37 or later. As a temporary workaround, consider restricting access to the vulnerable functions until a patch is available. However, since the issue is resolved in the mentioned kernel version, updating is the recommended course of action.
Note: The provided information does not specify the exact versions that are vulnerable, only that versions prior to 6.6.37 are affected. Therefore, updating to 6.6.37 or later is the recommended solution.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-11524
ALT-PU-2024-13979
ALT-PU-2024-14046
ALT-PU-2024-9127
AZL-42454
AZL-42478
BDU:2024-04561
CVE-2024-36938
DSA-5747-1
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-2029
OESA-2024-2031
OESA-2024-2076
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6949-1
USN-6949-2
USN-6950-1
USN-6950-2
USN-6950-3
USN-6950-4
USN-6952-1
USN-6952-2
USN-6955-1
USN-6956-1
USN-6957-1
USN-7019-1
USN-7159-1
USN-7159-2
USN-7159-3
USN-7159-4
USN-7159-5
USN-7195-1
USN-7195-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu