PT-2025-9974 · Linux+3 · Linux Kernel+3

Krzysztof Kozlowski

·

Published

2025-01-07

·

Updated

2025-05-28

·

CVE-2024-58084

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, related to a missing read barrier in the qcom scm get tzmem pool() function. This issue can cause the fetching of a stale scm variable value, potentially leading to a NULL pointer dereference. The problem arose from a commit that introduced a write barrier without a corresponding read barrier, which is necessary for accessing the scm variable from concurrent contexts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12206
CVE-2024-58084
USN-7521-1
USN-7521-2
USN-7521-3

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Ubuntu