NULL Pointer Dereference Affecting linux-6.1 package, versions <6.1.119-1~deb11u1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.22% (13th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN11-LINUX61-8601183
  • published2 Jan 2025
  • disclosed5 Nov 2024

Introduced: 5 Nov 2024

CVE-2024-50133  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade Debian:11 linux-6.1 to version 6.1.119-1~deb11u1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream linux-6.1 package and not the linux-6.1 package as distributed by Debian. See How to fix? for Debian:11 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

LoongArch: Don't crash in stack_top() for tasks without vDSO

Not all tasks have a vDSO mapped, for example kthreads never do. If such a task ever ends up calling stack_top(), it will derefence the NULL vdso pointer and crash.

This can for example happen when using kunit:

[&lt;9000000000203874&gt;] stack_top+0x58/0xa8
[&lt;90000000002956cc&gt;] arch_pick_mmap_layout+0x164/0x220
[&lt;90000000003c284c&gt;] kunit_vm_mmap_init+0x108/0x12c
[&lt;90000000003c1fbc&gt;] __kunit_add_resource+0x38/0x8c
[&lt;90000000003c2704&gt;] kunit_vm_mmap+0x88/0xc8
[&lt;9000000000410b14&gt;] usercopy_test_init+0xbc/0x25c
[&lt;90000000003c1db4&gt;] kunit_try_run_case+0x5c/0x184
[&lt;90000000003c3d54&gt;] kunit_generic_run_threadfn_adapter+0x24/0x48
[&lt;900000000022e4bc&gt;] kthread+0xc8/0xd4
[&lt;9000000000200ce8&gt;] ret_from_kernel_thread+0xc/0xa4

CVSS Base Scores

version 3.1