PT-2024-9780 · Linux+9 · Linux Kernel+9

Lizhe

·

Published

2024-04-12

·

Updated

2025-10-03

·

CVE-2024-38615

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.37
Description: The issue is related to the cpufreq component of the Linux kernel, where the exit() callback is optional and should not be called without checking a valid pointer first. Additionally, the freq table pointer must be cleared even if the exit() callback is not present. There is also a mention of a vulnerability in the ALSA component related to improper input validation in the snd timer start1() function, which could allow an attacker to cause a denial of service.
Recommendations: To resolve the issue, update the Linux kernel to version 6.6.37 or later. As a temporary workaround, consider disabling the vulnerable cpufreq component until a patch is available. Restrict access to the ALSA component to minimize the risk of exploitation. Avoid using the vulnerable snd timer start1() function until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:5101
ALSA-2024:5102
ALSA-2024:6997
ALSA-2025_16880
BDU:2024-11543
CESA-2024_5101
CESA-2024_5102
CVE-2024-38615
DSA-5730-1
INFSA-2024_5101
INFSA-2024_5102
INFSA-2024_6997
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1839
OESA-2024-1860
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4376-1
RHSA-2024:5101
RHSA-2024:5102
RHSA-2024:6744
RHSA-2024:6745
RHSA-2024:6993
RHSA-2024:6997
RHSA-2024_5101
RHSA-2024_5102
RHSA-2024_6997
RLSA-2024:5101
RLSA-2024:5102
RXSA-2024:5101
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4376-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6949-1
USN-6949-2
USN-6951-1
USN-6951-2
USN-6951-3
USN-6951-4
USN-6952-1
USN-6952-2
USN-6953-1
USN-6955-1
USN-6979-1
USN-7007-1
USN-7007-2
USN-7007-3
USN-7009-1
USN-7009-2
USN-7019-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu