Executive brief
A vulnerability in the Linux kernel's clock management system could allow a local user to cause a system crash. The clock system is responsible for managing the timing signals used by various hardware components. An exploit of this flaw results in a 'NULL pointer dereference,' leading to a kernel panic and immediate loss of system availability.
Technical details
A NULL pointer dereference vulnerability exists in the Linux kernel's clock framework (drivers/clk/clk.c). The function clk_core_get() fails to validate the return value of of_clk_get_hw_from_clkspec() and its underlying calls. Specifically, __clk_get_hw() can return a NULL pointer, which clk_core_get() then attempts to dereference at hw->core. This regression was introduced in commit dde4eff47c82 when an IS_ERR_OR_NULL() check was removed. A local attacker can trigger this condition to cause a kernel panic. Patches have been released across multiple stable kernel branches to re-introduce the necessary NULL check.
Affected products
- Linux Linux Kernel 5.2 to 5.4.273, 5.5 to 5.10.214, 5.11 to 5.15.153, 5.16 to 6.1.83, 6.2 to 6.6.23, 6.7 to 6.7.11, 6.8 to 6.8.2
Timeline
- 2024-03-26: patched: Fix committed to stable kernel trees
- 2024-05-01: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0efb9ef6fb95384ba631d6819e66f10392aabfa2
- https://git.kernel.org/stable/c/239174535dba11f7b83de0eaaa27909024f8c185
- https://git.kernel.org/stable/c/6f073b24a9e2becd25ac4505a9780a87e621bb51
- https://git.kernel.org/stable/c/a5d9b1aa61b401867b9066d54086b3e4ee91f8ed
- https://git.kernel.org/stable/c/a8b2b26fdd011ebe36d68a9a321ca45801685959
- https://git.kernel.org/stable/c/c554badcae9c45b737a22d23454170c6020b90e6
- https://git.kernel.org/stable/c/d7ae7d1265686b55832a445b1db8cdd69738ac07