PT-2025-2777 · Linux+5 · Linux Kernel+5

Alexander Aring

·

Published

2024-10-04

·

Updated

2026-05-26

·

CVE-2024-47809

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.74
Description: A possible null pointer dereference issue has been identified in the Linux kernel. This issue occurs when the request lock() function is called and lkb->lkb resource is not assigned yet, which happens before validate lock args() is called by attach lkb(). Another issue is that a resource name could be a non-printable bytearray, and it cannot be assumed to be ASCII coded. The log functionality is probably never hit when DLM is used normally and no debug logging is enabled. The null pointer dereference can only occur on a newly created lkb that does not have the resource assigned yet.
Recommendations: For Linux kernel versions prior to 6.6.74, update to version 6.6.74 or later to resolve the issue. As a temporary workaround, consider disabling the request lock() function until a patch is available. Restrict access to the dlm module to minimize the risk of exploitation. Avoid using the lkb resource variable in the affected code until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17881
ALT-PU-2024-17897
ALT-PU-2025-12647
AZL-56121
AZL-56166
BDU:2025-06483
CVE-2024-47809
ECHO-8EF0-B41B-1666
MGASA-2025-0030
MGASA-2025-0032
OESA-2025-1286
OESA-2025-1339
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0557-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:0565-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu