PT-2024-8407 · Linux+4 · Linux Kernel+4
Published
2024-03-26
·
Updated
2024-11-14
·
CVE-2024-35920
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions up to 6.6.26/6.8.5
Description
The issue is related to a null pointer dereference in the mediatek ctx list within the 'vpu dec ipi handler' function. This occurs when the ctx list has been deleted due to an unexpected behavior on the SCP IP block, leading to a kernel panic and potentially allowing privilege escalation. The vulnerability affects local networks.
Recommendations
To resolve the issue, update the Linux kernel to a version later than 6.6.26/6.8.5.
As a temporary workaround, consider disabling the 'vpu dec ipi handler' function until a patch is available.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu