CVE-2024-56620

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
27/12/2024
Last modified:
07/04/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> scsi: ufs: qcom: Only free platform MSIs when ESI is enabled<br /> <br /> Otherwise, it will result in a NULL pointer dereference as below:<br /> <br /> Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008<br /> Call trace:<br /> mutex_lock+0xc/0x54<br /> platform_device_msi_free_irqs_all+0x14/0x20<br /> ufs_qcom_remove+0x34/0x48 [ufs_qcom]<br /> platform_remove+0x28/0x44<br /> device_remove+0x4c/0x80<br /> device_release_driver_internal+0xd8/0x178<br /> driver_detach+0x50/0x9c<br /> bus_remove_driver+0x6c/0xbc<br /> driver_unregister+0x30/0x60<br /> platform_driver_unregister+0x14/0x20<br /> ufs_qcom_pltform_exit+0x18/0xb94 [ufs_qcom]<br /> __arm64_sys_delete_module+0x180/0x260<br /> invoke_syscall+0x44/0x100<br /> el0_svc_common.constprop.0+0xc0/0xe0<br /> do_el0_svc+0x1c/0x28<br /> el0_svc+0x34/0xdc<br /> el0t_64_sync_handler+0xc0/0xc4<br /> el0t_64_sync+0x190/0x194

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.3 (including) 6.12.5 (excluding)
cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:*