CVE-2024-46735
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: ublk_drv: fix NULL pointer dereference in ublk_ctrl_start_recovery() When two UBLK_CMD_START_USER_RECOVERY commands are submitted, the first one sets 'ubq->ubq_daemon' to NULL, and the second one triggers WARN in ublk_queue_reinit() and subsequently a NULL pointer dereference issue. Fix it by adding the check in ublk_ctrl_start_recovery() and return immediately in case of zero 'ub->nr_queues_ready'. BUG: kernel NULL pointer dereference, address: 0000000000000028 RIP: 0010:ublk_ctrl_start_recovery.constprop.0+0x82/0x180 Call Trace: <TASK> ? __die+0x20/0x70 ? page_fault_oops+0x75/0x170 ? exc_page_fault+0x64/0x140 ? asm_exc_page_fault+0x22/0x30 ? ublk_ctrl_start_recovery.constprop.0+0x82/0x180 ublk_ctrl_uring_cmd+0x4f7/0x6c0 ? pick_next_task_idle+0x26/0x40 io_uring_cmd+0x9a/0x1b0 io_issue_sqe+0x193/0x3f0 io_wq_submit_work+0x9b/0x390 io_worker_handle_work+0x165/0x360 io_wq_worker+0xcb/0x2f0 ? finish_task_switch.isra.0+0x203/0x290 ? finish_task_switch.isra.0+0x203/0x290 ? __pfx_io_wq_worker+0x10/0x10 ret_from_fork+0x2d/0x50 ? __pfx_io_wq_worker+0x10/0x10 ret_from_fork_asm+0x1a/0x30 </TASK>
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.02%• Percentile: 7%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- linux•linux
≥ c732a852b419fa057b53657e2daaf9433940391c, < ca249435893dda766f3845c15ca77ca5672022d8 | ≥ c732a852b419fa057b53657e2daaf9433940391c, < 136a29d8112df4ea0a57f9602ddf3579e04089dc | ≥ c732a852b419fa057b53657e2daaf9433940391c, < 7c890ef60bf417d3fe5c6f7a9f6cef0e1d77f74f | ≥ c732a852b419fa057b53657e2daaf9433940391c, < e58f5142f88320a5b1449f96a146f2f24615c5c7 | 6.1
- linux•linux_kernel
≥ 6.1, < 6.1.110 | ≥ 6.2, < 6.6.51 | ≥ 6.7, < 6.10.10 | 6.11:rc1 | 6.11:rc2 | 6.11:rc3 | 6.11:rc4 | 6.11:rc5 | 6.11:rc6
References (5)
- https://git.kernel.org/stable/c/ca249435893dda766f3845c15ca77ca5672022d8
- https://git.kernel.org/stable/c/136a29d8112df4ea0a57f9602ddf3579e04089dc
- https://git.kernel.org/stable/c/7c890ef60bf417d3fe5c6f7a9f6cef0e1d77f74f
- https://git.kernel.org/stable/c/e58f5142f88320a5b1449f96a146f2f24615c5c7
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html