CVE-2024-36476
Published: Jan 15, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Ensure 'ib_sge list' is accessible Move the declaration of the 'ib_sge list' variable outside the 'always_invalidate' block to ensure it remains accessible for use throughout the function. Previously, 'ib_sge list' was declared within the 'always_invalidate' block, limiting its accessibility, then caused a 'BUG: kernel NULL pointer dereference'[1]. ? __die_body.cold+0x19/0x27 ? page_fault_oops+0x15a/0x2d0 ? search_module_extables+0x19/0x60 ? search_bpf_extables+0x5f/0x80 ? exc_page_fault+0x7e/0x180 ? asm_exc_page_fault+0x26/0x30 ? memcpy_orig+0xd5/0x140 rxe_mr_copy+0x1c3/0x200 [rdma_rxe] ? rxe_pool_get_index+0x4b/0x80 [rdma_rxe] copy_data+0xa5/0x230 [rdma_rxe] rxe_requester+0xd9b/0xf70 [rdma_rxe] ? finish_task_switch.isra.0+0x99/0x2e0 rxe_sender+0x13/0x40 [rdma_rxe] do_task+0x68/0x1e0 [rdma_rxe] process_one_work+0x177/0x330 worker_thread+0x252/0x390 ? __pfx_worker_thread+0x10/0x10 This change ensures the variable is available for subsequent operations that require it. [1] https://lore.kernel.org/linux-rdma/[email protected]/
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 9cb837480424e78ed585376f944088246685aec3 - < 7eaa71f56a6f7ab87957213472dc6d4055862722affected 9cb837480424e78ed585376f944088246685aec3 - < 143378075904e78b3b2a810099bcc3b3d82d762faffected 9cb837480424e78ed585376f944088246685aec3 - < 32e1e748a85bd52b20b3857d80fd166d22fa455aaffected 9cb837480424e78ed585376f944088246685aec3 - < b238f61cc394d5fef27b26d7d9aa383ebfddabb0affected 9cb837480424e78ed585376f944088246685aec3 - < 6ffb5c1885195ae5211a12b4acd2d51843ca41b0+1 more versions |
Linux | Linux | affected 5.8unaffected 0 - < 5.8unaffected 5.10.233 - <= 5.10.*unaffected 5.15.176 - <= 5.15.*unaffected 6.1.124 - <= 6.1.*+3 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now