Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-26784— pmdomain: arm: Fix NULL dereference on scmi_perf_domain removal

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于空指针取消引用。

AI Predicted 5.5 Difficulty: Easy EPSS 0.19% · P10

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 6

VendorProduct Version RangeStatus
Linux Linux 2af23ceb8624a419eaf40295c11fcb86ec9ee303< f6aaf131e4d4a9a26040ecc018eb70ab8b3d355d affected
2af23ceb8624a419eaf40295c11fcb86ec9ee303< eb5555d422d0fc325e1574a7353d3c616f82d8b5 affected
6.7 affected
< 6.7 unaffected
6.7.9≤ 6.7.* unaffected
6.8≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-26784

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
pmdomain: arm: Fix NULL dereference on scmi_perf_domain removal
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: pmdomain: arm: Fix NULL dereference on scmi_perf_domain removal On unloading of the scmi_perf_domain module got the below splat, when in the DT provided to the system under test the '#power-domain-cells' property was missing. Indeed, this particular setup causes the probe to bail out early without giving any error, which leads to the ->remove() callback gets to run too, but without all the expected initialized structures in place. Add a check and bail out early on remove too. Call trace: scmi_perf_domain_remove+0x28/0x70 [scmi_perf_domain] scmi_dev_remove+0x28/0x40 [scmi_core] device_remove+0x54/0x90 device_release_driver_internal+0x1dc/0x240 driver_detach+0x58/0xa8 bus_remove_driver+0x78/0x108 driver_unregister+0x38/0x70 scmi_driver_unregister+0x28/0x180 [scmi_core] scmi_perf_domain_driver_exit+0x18/0xb78 [scmi_perf_domain] __arm64_sys_delete_module+0x1a8/0x2c0 invoke_syscall+0x50/0x128 el0_svc_common.constprop.0+0x48/0xf0 do_el0_svc+0x24/0x38 el0_svc+0x34/0xb8 el0t_64_sync_handler+0x100/0x130 el0t_64_sync+0x190/0x198 Code: a90153f3 f9403c14 f9414800 955f8a05 (b9400a80) ---[ end trace 0000000000000000 ]---
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 2af23ceb8624a419eaf40295c11fcb86ec9ee303 ~ f6aaf131e4d4a9a26040ecc018eb70ab8b3d355d -
Linux Linux 6.7 -

II. Public POCs for CVE-2024-26784

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-26784

登录查看更多情报信息。

Other References for CVE-2024-26784 (2)

Same Patch Batch · Linux · 2024-04-04 · 32 CVEs total

CVE-2024-26782 9.8 CRITICAL mptcp: fix double-free on socket dismantle
CVE-2024-26800 9.8 CRITICAL tls: fix use-after-free on failed backlog decryption
CVE-2024-26801 8.8 HIGH Bluetooth: Avoid potential use-after-free in hci_error_reset
CVE-2024-26793 7.8 HIGH gtp: fix use-after-free and null-ptr-deref in gtp_newlink()
CVE-2024-26809 7.8 HIGH netfilter: nft_set_pipapo: release elements in clone only from destroy path
CVE-2024-26808 7.8 HIGH netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain
CVE-2024-26807 7.8 HIGH spi: cadence-qspi: fix pointer reference in runtime PM hooks
CVE-2024-26804 7.8 HIGH net: ip_tunnel: prevent perpetual headroom growth
CVE-2024-26802 7.8 HIGH stmmac: Clear variable when destroying workqueue
CVE-2024-26797 7.8 HIGH drm/amd/display: Prevent potential buffer overflow in map_hw_resources
CVE-2024-26795 7.8 HIGH riscv: Sparse-Memory/vmemmap out-of-bounds fix
CVE-2024-26792 7.8 HIGH btrfs: fix double free of anonymous device after snapshot creation failure
CVE-2024-26789 7.8 HIGH crypto: arm64/neonbs - fix out-of-bounds access on short input
CVE-2024-26786 7.8 HIGH iommufd: Fix iopt_access_list_id overwrite bug
CVE-2024-26799 7.0 HIGH ASoC: qcom: Fix uninitialized pointer dmactl
CVE-2024-26746 dmaengine: idxd: Ensure safe user copy of completion record
CVE-2024-26790 dmaengine: fsl-qdma: fix SoC may hang on 16 byte unaligned read
CVE-2024-26750 af_unix: Drop oob_skb ref before purging queue in GC.
CVE-2024-26780 af_unix: Fix task hung while purging oob_skb in GC.
CVE-2024-26806 spi: cadence-qspi: remove system-wide suspend helper calls from runtime PM hooks

Showing top 20 of 32 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-26784

No comments yet


Leave a comment