Junglewise Threat Intelligence

CVE-2024-35984: Linux Kernel NULL pointer dereference in I2C SMBus

CVE-2024-35984 · Severity: medium · CVSS 5.5 · Published 2024-05-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's I2C/SMBus component could allow a local user to cause a system crash. The issue occurs when certain hardware controllers are used in 'target-only' mode, leading to a kernel panic (OOPS). This affects the availability of the system but does not directly expose sensitive data.

Technical details

A NULL pointer dereference exists in the Linux kernel's I2C core (specifically in drivers/i2c/i2c-core-base.c). The vulnerability is triggered when an I2C controller, such as the DesignWare controller, is configured in target-only mode. In this configuration, the 'master_xfer' function pointer may be NULL, but the kernel previously assumed a transfer function would always be available. An attacker with local access could trigger this NULL dereference via the __i2c_transfer function, resulting in a kernel OOPS and denial of service. The fix involves adding a mandatory check for the master_xfer pointer before use. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 3.19 to 4.19.313, 4.20 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.158, 5.16 to 6.1.90, 6.2 to 6.6.30, 6.7 to 6.8.9

Timeline

  • 2024-04-26: patched: Initial patch authored by Wolfram Sang
  • 2024-05-20: disclosed: CVE published

References

Related threats