PT-2024-9794 · Linux+5 · Linux Kernel+5

Romain Gantois

·

Published

2024-05-23

·

Updated

2025-09-29

·

CVE-2024-38584

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to a NULL pointer dereference in the prueth probe() function. If one of the calls to emac phy connect() fails due to of phy connect() returning NULL, then the subsequent call to phy attached info() will dereference a NULL pointer. This can be exploited to cause a denial of service. The vulnerability is resolved by checking the return code of emac phy connect() and failing cleanly if there is an error.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13979
BDU:2024-11568
CVE-2024-38584
MGASA-2024-0263
MGASA-2024-0266
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu