PT-2024-9020 · Linux+5 · Linux Kernel+5

Nikita Ioffe

·

Published

2024-05-30

·

Updated

2025-09-29

·

CVE-2024-36925

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the swiotlb component of the Linux kernel. It occurs when using restricted DMA pools in conjunction with dynamic SWIOTLB, leading to a crash at boot-time due to a NULL pointer dereference. The crash happens because the add mem pool() function tries to add to a NULL mem->pools list. The problem can be fixed by initializing the mem->pools list head in rmem swiotlb device init() before calling add mem pool().
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13979
AZL-42462
BDU:2024-10702
CVE-2024-36925
MGASA-2024-0263
MGASA-2024-0266
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu