NULL pointer dereference in Linux kernel - CVE-2024-26649

 

NULL pointer dereference in Linux kernel - CVE-2024-26649

Published: May 31, 2024 / Updated: May 14, 2025


Vulnerability identifier: #VU90613
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26649
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the gfx_v10_0_init_microcode() function in drivers/gpu/drm/amd/amdgpu/gfx_v10_0.c. A local user can perform a denial of service (DoS) attack.


Affected software

Linux kernel
Oracle Linux
Anolis OS
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
Ubuntu
IBM Integrated Analytics System
Storage Copy Data Management
Cloud Pak for Network Automation
Technical Support Appliance
IBM Cloud Pak for Watson AIOps
Red Hat OpenShift Container Platform
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel-debug
bpftool
kernel
kernel-core
kernel-cross-headers
python3-perf
kernel-debug-core
kernel-debug-devel
kernel-debug-modules
kernel-debug-modules-extra
kernel-devel
kernel-headers
kernel-modules
kernel-modules-extra
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
kernel-doc
kernel-abi-stablelists
linux-image-virtual-hwe-22.04 (Ubuntu package)
linux-image-generic-hwe-22.04 (Ubuntu package)
linux-image-generic-64k-hwe-22.04 (Ubuntu package)
linux-image-6.5.0-41-generic-64k (Ubuntu package)
linux-image-6.5.0-41-generic (Ubuntu package)
linux-image-6.5.0-1017-laptop (Ubuntu package)
linux-image-laptop-23.10 (Ubuntu package)
linux-image-6.5.0-1021-nvidia-64k (Ubuntu package)
linux-image-6.5.0-1021-nvidia (Ubuntu package)
linux-image-nvidia-64k-hwe-22.04 (Ubuntu package)
linux-image-nvidia-6.5 (Ubuntu package)
linux-image-nvidia-64k-6.5 (Ubuntu package)
linux-image-nvidia-hwe-22.04 (Ubuntu package)
linux-image-6.5.0-1022-oem (Ubuntu package)
linux-image-oem-22.04 (Ubuntu package)
linux-image-oem-22.04b (Ubuntu package)
linux-image-oem-22.04a (Ubuntu package)
linux-image-oem-22.04d (Ubuntu package)
linux-image-oem-22.04c (Ubuntu package)
OpenShift Logging

How to mitigate CVE-2024-26649

Install update from vendor's website.

Linux kernel - addressed in versions 6.6.15, 6.7.3, 6.8
IBM Integrated Analytics System - update to 1.0.31.0
Storage Copy Data Management - update to 2.2.25.0
Cloud Pak for Network Automation - update to 2.7.7
Technical Support Appliance - update to 3.0.1
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.52, 4.14.38, 4.15.35
kernel (Red Hat package) - update to 4.18.0-553.22.1.el8_10
kernel-rt (Red Hat package) - update to 4.18.0-553.22.1.rt7.363.el8_10
kernel-debug - update to 4.18.0-553.22.1.0.1
bpftool - update to 4.18.0-553.22.1.0.1
kernel - update to 4.18.0-553.22.1.0.1
kernel-core - update to 4.18.0-553.22.1.0.1
kernel-cross-headers - update to 4.18.0-553.22.1.0.1
python3-perf - update to 4.18.0-553.22.1.0.1
kernel-debug-core - update to 4.18.0-553.22.1.0.1
kernel-debug-devel - update to 4.18.0-553.22.1.0.1
kernel-debug-modules - update to 4.18.0-553.22.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.22.1.0.1
kernel-devel - update to 4.18.0-553.22.1.0.1
kernel-headers - update to 4.18.0-553.22.1.0.1
kernel-modules - update to 4.18.0-553.22.1.0.1
kernel-modules-extra - update to 4.18.0-553.22.1.0.1
kernel-tools - update to 4.18.0-553.22.1.0.1
kernel-tools-libs - update to 4.18.0-553.22.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.22.1.0.1
perf - update to 4.18.0-553.22.1.0.1
kernel-doc - update to 4.18.0-553.22.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.22.1.0.1
OpenShift Logging - update to 5.6.25
linux-image-virtual-hwe-22.04 (Ubuntu package) - update to 6.5.0.41.41~22.04.2
linux-image-generic-hwe-22.04 (Ubuntu package) - update to 6.5.0.41.41~22.04.2
linux-image-generic-64k-hwe-22.04 (Ubuntu package) - update to 6.5.0.41.41~22.04.2
linux-image-6.5.0-41-generic-64k (Ubuntu package) - update to 6.5.0-41.41~22.04.2
linux-image-6.5.0-41-generic (Ubuntu package) - update to 6.5.0-41.41~22.04.2
linux-image-6.5.0-1017-laptop (Ubuntu package) - update to 6.5.0-1017.20
linux-image-laptop-23.10 (Ubuntu package) - update to 6.5.0.1017.20
linux-image-6.5.0-1021-nvidia-64k (Ubuntu package) - update to 6.5.0-1021.22
linux-image-6.5.0-1021-nvidia (Ubuntu package) - update to 6.5.0-1021.22
linux-image-nvidia-64k-hwe-22.04 (Ubuntu package) - update to 6.5.0.1021.29
linux-image-nvidia-6.5 (Ubuntu package) - update to 6.5.0.1021.29
linux-image-nvidia-64k-6.5 (Ubuntu package) - update to 6.5.0.1021.29
linux-image-nvidia-hwe-22.04 (Ubuntu package) - update to 6.5.0.1021.29
linux-image-6.5.0-1022-oem (Ubuntu package) - update to 6.5.0-1022.23
linux-image-oem-22.04 (Ubuntu package) - update to 6.5.0.1022.24
linux-image-oem-22.04b (Ubuntu package) - update to 6.5.0.1022.24
linux-image-oem-22.04a (Ubuntu package) - update to 6.5.0.1022.24
linux-image-oem-22.04d (Ubuntu package) - update to 6.5.0.1022.24
linux-image-oem-22.04c (Ubuntu package) - update to 6.5.0.1022.24

External References

Related Security Bulletins