PT-2025-3673 · Linux+7 · Linux Kernel+7

Syzbot

·

Published

2024-11-13

·

Updated

2025-10-03

·

CVE-2024-57948

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.15.177, 6.1.127, 6.6.74, and 6.12.11
Description The issue is related to the ieee802154 if remove() function in the Linux kernel, which is responsible for removing an IEEE 802.15.4 network interface. The problem arises due to insufficient input validation, leading to a corrupted list and potential denial-of-service. The vulnerability can be exploited by removing an IEEE 802.15.4 network interface after unregistering an IEEE 802.15.4 hardware device from the system. Technical details include the list del(&sdata->list) and ieee802154 if remove() functions, as well as the genl family rcv msg doit() and ieee802154 del iface() functions.
Recommendations To resolve the issue, update the Linux kernel to version 5.15.177, 6.1.127, 6.6.74, or 6.12.11, or later. As a temporary workaround, consider adding a check for local interfaces before deleting the sdata list in the ieee802154 if remove() function. Restrict access to the ieee802154 if remove() function to minimize the risk of exploitation. Avoid using the list del(&sdata->list) function in the affected API endpoint until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12647
BDU:2025-01483
CVE-2024-57948
DLA-4075-1
DLA-4076-1
DSA-5860-1
OESA-2025-2077
OESA-2025-2078
OESA-2025-2079
OPENSUSE-SU-2025_0833-1
OPENSUSE-SU-2025_0835-1
OPENSUSE-SU-2025_0847-1
OPENSUSE-SU-2025_0853-1
OPENSUSE-SU-2025_0856-1
OPENSUSE-SU-2025_0955-1
SUSE-SU-2025:0784-1
SUSE-SU-2025:0833-1
SUSE-SU-2025:0833-2
SUSE-SU-2025:0835-1
SUSE-SU-2025:0847-1
SUSE-SU-2025:0853-1
SUSE-SU-2025:0856-1
SUSE-SU-2025:0945-1
SUSE-SU-2025:0955-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_0833-1
SUSE-SU-2025_0833-2
SUSE-SU-2025_0835-1
SUSE-SU-2025_0847-1
SUSE-SU-2025_0856-1
SUSE-SU-2025_0955-1
USN-7387-1
USN-7387-2
USN-7387-3
USN-7388-1
USN-7389-1
USN-7390-1
USN-7391-1
USN-7392-1
USN-7392-2
USN-7392-3
USN-7392-4
USN-7393-1
USN-7401-1
USN-7407-1
USN-7413-1
USN-7421-1
USN-7445-1
USN-7448-1
USN-7458-1
USN-7459-1
USN-7459-2
USN-7463-1
USN-7539-1
USN-7540-1
USN-7595-1
USN-7595-2
USN-7595-3
USN-7595-4
USN-7595-5
USN-7596-1
USN-7596-2
USN-7653-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu