Junglewise Threat Intelligence

CVE-2024-27047: Linux Kernel NULL pointer dereference in phy_get_internal_delay

CVE-2024-27047 · Severity: medium · CVSS 5.5 · Published 2024-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash. The issue occurs when certain network hardware drivers attempt to process specific configuration values, leading to a 'kernel oops' or system failure. This primarily impacts the availability of the affected system.

Technical details

A NULL pointer dereference exists in the 'phy_get_internal_delay' function within 'drivers/net/phy/phy_device.c'. The vulnerability is triggered when a driver calls this function without defining 'delay_values' while 'rx-internal-delay-ps' or 'tx-internal-delay-ps' is set to 0 in the device-tree. Under these conditions, the function attempts to access an empty array, leading to a kernel oops. An attacker with local access could potentially exploit this to cause a Denial of Service (DoS). The issue has been resolved by ensuring the function correctly handles cases where the array size is zero.

Affected products

  • Linux Linux Kernel 5.9 to 5.10.214, 5.11 to 5.15.153, 5.16 to 6.1.83, 6.2 to 6.6.23, 6.7 to 6.7.11, 6.8 to 6.8.2

Timeline

  • 2024-05-01: disclosed
  • 2024-03-26: patched: Patched in various stable branches including 5.10, 5.15, 6.1, 6.6, 6.7, and 6.8

References

Related threats