PT-2024-9025 · Linux+4 · Linux Kernel+4

Published

2024-05-30

·

Updated

2024-11-27

·

CVE-2024-36888

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The vulnerability is related to the workqueue component in the Linux kernel. It causes a crash when calling arch vcpu is preempted() for an offline CPU. The issue arises due to the selection of wake cpu in kick pool(). To avoid this, the CPU should be selected with cpumask any and distribute() to mask pod cpumask with cpu online mask. In case no CPU is left in the pool, the assignment should be skipped. The crash is observed with cpu possible mask=0-63 and cpu online mask=0-7. The call trace includes functions such as select idle sibling(), select task rq fair(), try to wake up(), and kick pool(). The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10707
CVE-2024-36888
MGASA-2024-0263
MGASA-2024-0266
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu