CVE-2024-50176

MEDIUM

Linux Kernel 6.1.95-6.1.112 - Denial of Service via Remoteproc Power-Up Failure

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: remoteproc: k3-r5: Fix error handling when power-up failed By simply bailing out, the driver was violating its rule and internal assumptions that either both or no rproc should be initialized. E.g., this could cause the first core to be available but not the second one, leading to crashes on its shutdown later on while trying to dereference that second instance.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-755
Status published
Products (17)
Linux/Linux < 6.10
Linux/Linux 2494bc856e7ce50b1c4fd8afb4d17f2693f36565 - fc71c23958931713b5e76f317b76be37189f2516
Linux/Linux 2a1ec20b174c0f613224c59e694639ac07308b53 - 87ab3af7447791d0c619610fd560bd804549e187
Linux/Linux 6.1.113 - 6.1.*
Linux/Linux 6.1.95 - 6.1.113
Linux/Linux 6.10
Linux/Linux 6.10.14 - 6.10.*
Linux/Linux 6.11.3 - 6.11.*
Linux/Linux 6.12
Linux/Linux 6.6.35 - 6.6.55
... and 7 more
Published Nov 08, 2024
Tracked Since Feb 18, 2026