cbcvebase.
CVE-2024-47809
published 2025-01-11

CVE-2024-47809: In the Linux kernel, the following vulnerability has been resolved: dlm: fix possible lkb_resource null dereference This patch fixes a possible null pointer…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: dlm: fix possible lkb_resource null dereference This patch fixes a possible null pointer dereference when this function is called from request_lock() as lkb->lkb_resource is not assigned yet, only after validate_lock_args() by calling attach_lkb(). Another issue is that a resource name could be a non printable bytearray and we cannot assume to be ASCII coded. The log functionality is probably never being hit when DLM is used in normal way and no debug logging is enabled. The null pointer dereference can only occur on a new created lkb that does not have the resource assigned yet, it probably never hits the null pointer dereference but we should be sure that other changes might not change this behaviour and we actually can hit the mentioned null pointer dereference. In this patch we just drop the printout of the resource name, the lkb id is enough to make a possible connection to a resource name if this exists.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.5-1 (forky)linux 6.12.5-1 (forky)
linuxlinux
linuxlinux>= 43279e5376017c40b4be9af5bc79cbb4ef6f53d7 < e1ffea6bec96d4349dbfcc42ad3e436259f64243e1ffea6bec96d4349dbfcc42ad3e436259f64243
linuxlinux>= 43279e5376017c40b4be9af5bc79cbb4ef6f53d7 < 8d55ce46dd543c6965970ce70c22c3076dd35b1e8d55ce46dd543c6965970ce70c22c3076dd35b1e
linuxlinux>= 43279e5376017c40b4be9af5bc79cbb4ef6f53d7 < 6fbdc3980b70e9c1c86eccea7d5ee68108008fa76fbdc3980b70e9c1c86eccea7d5ee68108008fa7
linuxlinux>= 43279e5376017c40b4be9af5bc79cbb4ef6f53d7 < 2db11504ef82a60c1a2063ba7431a5cd013ecfcb2db11504ef82a60c1a2063ba7431a5cd013ecfcb
linuxlinux>= 43279e5376017c40b4be9af5bc79cbb4ef6f53d7 < b98333c67daf887c724cd692e88e2db9418c0861b98333c67daf887c724cd692e88e2db9418c0861
linuxlinux_kernel< 6.6.666.6.66
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 6.7 < 6.12.56.12.5
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure-5.15
ubuntulinux-azure-fde
ubuntulinux-azure-fde-5.15
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop
ubuntulinux-hwe-5.15

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.