In the Linux kernel, the following vulnerability has been resolved:
misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge
There is an issue with the ASPM(optional) capability checking function. A device might be attached to root complex directly, in this case, bus->self(bridge) will be NULL, thus priv->parent_pdev is NULL. Since alcor_pci_init_check_aspm(priv->parent_pdev) checks the PCI link's ASPM capability and populate parent_cap_off, which will be used later by alcor_pci_aspm_ctrl() to dynamically turn on/off device, what we can do here is to avoid checking the capability if we are on the root complex. This will make pdev_cap_off 0 and alcor_pci_aspm_ctrl() will simply return when bring called, effectively disable ASPM for the device.
[ 1.246492] BUG: kernel NULL pointer dereference, address: 00000000000000c0 [ 1.248731] RIP: 0010:pci_read_config_byte+0x5/0x40 [ 1.253998] Call Trace: [ 1.254131] ? alcor_pci_find_cap_offset.isra.0+0x3a/0x100 [alcor_pci] [ 1.254476] alcor_pci_probe+0x169/0x2d5 [alcor_pci]
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | May 21, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 21, 2024 |
| Suse | — | Upgrade kernel-zfcpdumpUpgrade kernel-obs-buildUpgrade kernel-default-develUpgrade kernel-sourceUpgrade kernel-preempt-develUpgrade kernel-64kbUpgrade reiserfs-kmp-defaultUpgrade kernel-preemptUpgrade kernel-develUpgrade kernel-macrosUpgrade kernel-default-baseUpgrade kernel-symsUpgrade kernel-64kb-develUpgrade kernel-docsUpgrade kernel-default | Aug 9, 2024 | May 21, 2024 |
| Ubuntu | — | Upgrade linux-awsUpgrade linux-oracle-5.4Upgrade linux-fipsUpgrade linux-aws-5.4Upgrade linux-bluefieldUpgrade linux-raspi-5.4Upgrade linux-kvmUpgrade linux-azureUpgrade linux-raspiUpgrade linux-gcp-fipsUpgrade linux-ibmUpgrade linux-azure-fipsUpgrade linuxUpgrade linux-hwe-5.4Upgrade linux-azure-5.4Upgrade linux-oracleUpgrade linux-azure-fde-5.15Upgrade linux-gcp-5.4Upgrade linux-gcpUpgrade linux-gkeopUpgrade linux-aws-fips | Nov 19, 2024 | May 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub