cbcvebase.
CVE-2024-36893
published 2024-05-30

CVE-2024-36893: In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: Check for port partner validity before consuming it…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.5th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: Check for port partner validity before consuming it typec_register_partner() does not guarantee partner registration to always succeed. In the event of failure, port->partner is set to the error value or NULL. Given that port->partner validity is not checked, this results in the following crash: Unable to handle kernel NULL pointer dereference at virtual address xx pc : run_state_machine+0x1bc8/0x1c08 lr : run_state_machine+0x1b90/0x1c08 .. Call trace: run_state_machine+0x1bc8/0x1c08 tcpm_state_machine_work+0x94/0xe4 kthread_worker_fn+0x118/0x328 kthread+0x1d0/0x23c ret_from_fork+0x10/0x20 To prevent the crash, check for port->partner validity before derefencing it in all the call sites.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 31220bd89c22a18478f52fcd8069e8e2adb8f4f2 < 2a07e6f0ad8a6e504a3912cfe8dc859b7d0740a52a07e6f0ad8a6e504a3912cfe8dc859b7d0740a5
linuxlinux>= 5.15.132 < 5.15.1685.15.168
linuxlinux>= 6.1.53 < 6.1.916.1.91
linuxlinux>= 6.4.16 < 6.56.5
linuxlinux>= 6.5.3 < 6.66.6
linuxlinux>= 9b7cd3fe01f0d03cf5820b351a6be2a6e0a6da6f < d56d2ca03cc22123fd7626967d096d8661324e57d56d2ca03cc22123fd7626967d096d8661324e57
linuxlinux>= c97cd0b4b54eb42aed7f6c3c295a2d137f6d2416 < 789326cafbd1f67f424436b6bc8bdb887a364637789326cafbd1f67f424436b6bc8bdb887a364637
linuxlinux>= c97cd0b4b54eb42aed7f6c3c295a2d137f6d2416 < fc2b655cb6dd2b381f1f284989721002e39b6b77fc2b655cb6dd2b381f1f284989721002e39b6b77
linuxlinux>= c97cd0b4b54eb42aed7f6c3c295a2d137f6d2416 < ae11f04b452b5205536e1c02d31f8045eba249ddae11f04b452b5205536e1c02d31f8045eba249dd
linuxlinux_kernel< 6.1.916.1.91
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 6.2 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10
msrcazl3_kernel_6.6.29.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.35.1-4_on_azure_linux_3.0
msrccbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.