PT-2024-9005 · Linux+8 · Linux Kernel+8

Alexandra Winter

·

Published

2024-05-30

·

Updated

2026-03-14

·

CVE-2024-36928

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.37
Description: The vulnerability is related to the s390/qeth component of the Linux kernel. When the hsuid attribute is set for the first time on an IQD Layer3 device while the corresponding network interface is already UP, the kernel will try to execute a napi function pointer that is NULL. This can cause a kernel panic.
Technical details about exploitation include:
  • The napi.poll functions are set during qeth open().
  • The qeth set offline()/qeth set online() functions no longer call dev close()/dev open() due to commit 1cfef80d4c2b ("s390/qeth: Don't call dev close/dev open (DOWN/UP)").
  • If qeth free qdio queues() cleared card->qdio.out qs[i].napi.poll while the network interface was UP and the card was offline, they are not set again.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-10687
CESA-2024_5101
CVE-2024-36928
INFSA-2024_9315
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1707
OESA-2024-1737
OESA-2024-1766
RHSA-2024:10771
RHSA-2024:10772
RHSA-2024:5101
RHSA-2024:9315
RHSA-2024_5101
RHSA-2024_9315
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
USN-6949-1
USN-6949-2
USN-6950-1
USN-6950-2
USN-6950-3
USN-6950-4
USN-6952-1
USN-6952-2
USN-6955-1
USN-6956-1
USN-6957-1
USN-7019-1

Affected Products

Astra Linux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu