PT-2024-8407 · Linux+4 · Linux Kernel+4

Published

2024-03-26

·

Updated

2024-11-14

·

CVE-2024-35920

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions up to 6.6.26/6.8.5
Description The issue is related to a null pointer dereference in the mediatek ctx list within the 'vpu dec ipi handler' function. This occurs when the ctx list has been deleted due to an unexpected behavior on the SCP IP block, leading to a kernel panic and potentially allowing privilege escalation. The vulnerability affects local networks.
Recommendations To resolve the issue, update the Linux kernel to a version later than 6.6.26/6.8.5. As a temporary workaround, consider disabling the 'vpu dec ipi handler' function until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09966
CVE-2024-35920
USN-6893-1
USN-6893-2
USN-6893-3
USN-6918-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu