CVE-2024-56620
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
27/12/2024
Last modified:
07/04/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
scsi: ufs: qcom: Only free platform MSIs when ESI is enabled<br />
<br />
Otherwise, it will result in a NULL pointer dereference as below:<br />
<br />
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008<br />
Call trace:<br />
mutex_lock+0xc/0x54<br />
platform_device_msi_free_irqs_all+0x14/0x20<br />
ufs_qcom_remove+0x34/0x48 [ufs_qcom]<br />
platform_remove+0x28/0x44<br />
device_remove+0x4c/0x80<br />
device_release_driver_internal+0xd8/0x178<br />
driver_detach+0x50/0x9c<br />
bus_remove_driver+0x6c/0xbc<br />
driver_unregister+0x30/0x60<br />
platform_driver_unregister+0x14/0x20<br />
ufs_qcom_pltform_exit+0x18/0xb94 [ufs_qcom]<br />
__arm64_sys_delete_module+0x180/0x260<br />
invoke_syscall+0x44/0x100<br />
el0_svc_common.constprop.0+0xc0/0xe0<br />
do_el0_svc+0x1c/0x28<br />
el0_svc+0x34/0xdc<br />
el0t_64_sync_handler+0xc0/0xc4<br />
el0t_64_sync+0x190/0x194
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.3 (including) | 6.12.5 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



