cbcvebase.
CVE-2024-41055
published 2024-07-29

CVE-2024-41055: In the Linux kernel, the following vulnerability has been resolved: mm: prevent derefencing NULL ptr in pfn_section_valid() Commit 5ec8e8ea8b77 ("mm/sparsemem…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved: mm: prevent derefencing NULL ptr in pfn_section_valid() Commit 5ec8e8ea8b77 ("mm/sparsemem: fix race in accessing memory_section->usage") changed pfn_section_valid() to add a READ_ONCE() call around "ms->usage" to fix a race with section_deactivate() where ms->usage can be cleared. The READ_ONCE() call, by itself, is not enough to prevent NULL pointer dereference. We need to check its value before dereferencing it.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.10.210 < 5.10.2225.10.222
linuxlinux>= 5.15.149 < 5.15.1635.15.163
linuxlinux>= 5ec8e8ea8b7783fab150cf86404fc38cb4db8800 < adccdf702b4ea913ded5ff512239e382d7473b63adccdf702b4ea913ded5ff512239e382d7473b63
linuxlinux>= 5ec8e8ea8b7783fab150cf86404fc38cb4db8800 < 82f0b6f041fad768c28b4ad05a683065412c226e82f0b6f041fad768c28b4ad05a683065412c226e
linuxlinux>= 6.1.76 < 6.1.1006.1.100
linuxlinux>= 6.6.15 < 6.6.416.6.41
linuxlinux>= 6.7.3 < 6.86.8
linuxlinux>= 68ed9e33324021e9d6b798e9db00ca3093d2012a < 941e816185661bf2b44b488565d09444ae316509941e816185661bf2b44b488565d09444ae316509
linuxlinux>= 70064241f2229f7ba7b9599a98f68d9142e81a97 < 797323d1cf92d09b7a017cfec576d9babf99cde7797323d1cf92d09b7a017cfec576d9babf99cde7
linuxlinux>= 90ad17575d26874287271127d43ef3c2af876cea < 0100aeb8a12d51950418e685f879cc80cb8e59820100aeb8a12d51950418e685f879cc80cb8e5982
linuxlinux>= b448de2459b6d62a53892487ab18b7d823ff0529 < bc17f2377818dca643a74499c3f5333500c90503bc17f2377818dca643a74499c3f5333500c90503
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.10.219 < 5.10.2225.10.222
linuxlinux_kernel>= 5.15.149 < 5.15.1635.15.163
linuxlinux_kernel>= 6.1.76 < 6.1.1006.1.100
linuxlinux_kernel>= 6.6.15 < 6.6.416.6.41

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.