CVE-2024-27038
Last modified
CVE-2024-27038 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: clk: Fix clk_core_get NULL dereference It is possible for clk_core_get to dereference a NULL in the following sequence: clk_core_get() of_clk_get_hw_from_clkspec() __of_clk_get_hw_from_provider() __clk_get_hw() __clk_get_hw() can return NULL which is dereferenced by clk_core_get() at hw->core. Prior to commit dde4eff47c82 ("clk: Look for parents with clkdev based clk_lookups") the check IS_ERR_OR_NULL() was performed which would have caught the NULL. Reading the description of this function it talks about returning NULL but that cannot be so at the moment. Update the function to check for hw before dereferencing it and return NULL if hw is NULL.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: clk: Fix clk_core_get NULL dereference It is possible for clk_core_get to dereference a NULL in the following sequence: clk_core_get() of_clk_get_hw_from_clkspec() __of_clk_get_hw_from_provider() __clk_get_hw() __clk_get_hw() can return NULL which is dereferenced by clk_core_get() at hw->core. Prior to commit dde4eff47c82 ("clk: Look for parents with clkdev based clk_lookups") the check IS_ERR_OR_NULL() was performed which would have caught the NULL. Reading the description of this function it talks about returning NULL but that cannot be so at the moment. Update the function to check for hw before dereferencing it and return NULL if hw is NULL.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.2, < 5.4.273 |
| Linux | Linux Kernel | >= 5.5, < 5.10.214 |
| Linux | Linux Kernel | >= 5.11, < 5.15.153 |
| Linux | Linux Kernel | >= 5.16, < 6.1.83 |
| Linux | Linux Kernel | >= 6.2, < 6.6.23 |
| Linux | Linux Kernel | >= 6.7, < 6.7.11 |
| Linux | Linux Kernel | >= 6.8, < 6.8.2 |
| Debian | Debian Linux | 10.0 |
References
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-27038?
How severe is CVE-2024-27038?
How do I fix CVE-2024-27038?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-27032In the Linux kernel, the following vulnerability has been re…6.3
- CVE-2024-27033In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-27034In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-27035In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-27036In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-27037In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-27039In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-2704A vulnerability classified as critical was found in Tenda AC…8.8
- CVE-2024-27040In the Linux kernel, the following vulnerability has been re…4.7
- CVE-2024-27041In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-27042Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-27043In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2024-27038?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
