PT-2024-8492 · Linux+8 · Linux Kernel+8

David Thompson

·

Published

2024-03-29

·

Updated

2025-09-29

·

CVE-2024-35885

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.15.0-bf.6.gef6992a
Description The vulnerability is related to the mlxbf gige driver in the Linux kernel, which encounters a NULL pointer exception during system shutdown via the "reboot" command. This exception occurs because the driver's shutdown() method is always executed, but the stop() method may not be executed if the networking interface configuration logic is not properly set up. As a result, NAPI remains enabled, leading to a potential exception if NAPI is scheduled while the hardware interface is partially deinitialized. The issue can cause a kernel panic and prevent the system from shutting down properly.
Recommendations To resolve this issue, ensure that the networking interface managed by the mlxbf gige driver is properly stopped during system shutdown. This can be achieved by setting up the networking interface configuration logic within the Linux distribution to execute the stop() method. Additionally, consider updating to a newer version of the Linux kernel, such as 5.15.0-bf.6.gef6992a or later, which includes the resolved vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4928
ALSA-2025_16880
BDU:2024-10052
CVE-2024-35885
INFSA-2024_4928
RHSA-2024:4928
RHSA-2024:5066
RHSA-2024:5067
RHSA-2024_4928
RLSA-2024:4928
RXSA-2024:4928
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
USN-6893-1
USN-6893-2
USN-6893-3
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6918-1
USN-6919-1
USN-6927-1
USN-7019-1

Affected Products

Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu