PT-2025-3578 · Linux+3 · Linux Kernel+3

Dmitry Osipenko

·

Published

2024-12-08

·

Updated

2025-09-29

·

CVE-2024-57799

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises from the potential invocation of rk hdptx phy runtime resume() before platform set drvdata() is executed in the ->probe() function, leading to a NULL pointer dereference when using the return of dev get drvdata(). This occurs in the Linux kernel, specifically in the phy: rockchip: samsung-hdptx component. The problem is resolved by ensuring that platform set drvdata() is called before devm pm runtime enable().
Recommendations Ensure platform set drvdata() is called before devm pm runtime enable() to prevent the NULL pointer dereference. As a temporary workaround, consider restricting the use of the rk hdptx phy runtime resume() function until the issue is fully resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2025-1925
ALT-PU-2025-3483
BDU:2025-15366
CVE-2024-57799
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Ubuntu