PT-2024-7366 · Linux+4 · Linux Kernel+4

Yunseong Kim

·

Published

2024-07-09

·

Updated

2025-09-29

·

CVE-2024-42235

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the functions crst table free() and base crst free() in the Linux kernel's memory management subsystem on the s390 platform. The problem arises from the potential dereference of a null pointer. In real-life scenarios, this should not occur because order two GFP KERNEL allocations will not fail unless FAIL PAGE ALLOC is enabled and used. The vulnerability could allow an attacker to cause a denial of service.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13979
AZL-47543
BDU:2024-08730
CVE-2024-42235
OESA-2024-2124
USN-7089-1
USN-7089-2
USN-7089-3
USN-7089-4
USN-7089-5
USN-7089-6
USN-7089-7
USN-7090-1
USN-7095-1
USN-7156-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu