NULL pointer dereference in Linux kernel - CVE-2024-35920
Published: May 31, 2024 / Updated: May 14, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the vpu_dec_check_ap_inst() function in drivers/media/platform/mediatek/vcodec/decoder/vdec_vpu_if.c, within the fops_vcodec_open(), fops_vcodec_release() and mtk_vcodec_probe() functions in drivers/media/platform/mediatek/vcodec/decoder/mtk_vcodec_dec_drv.c, within the mtk_vcodec_vpu_reset_dec_handler() function in drivers/media/platform/mediatek/vcodec/common/mtk_vcodec_fw_vpu.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/0a2dc707aa42214f9c4827bd57e344e29a0841d6
- https://git.kernel.org/stable/c/23aaf824121055ba81b55f75444355bd83c8eb38
- https://git.kernel.org/stable/c/6467cda18c9f9b5f2f9a0aa1e2861c653e41f382
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.27
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8.6