In the Linux kernel, the following vulnerability has been resolved:
thermal/debugfs: Fix two locking issues with thermal zone debug
With the current thermal zone locking arrangement in the debugfs code, user space can open the "mitigations" file for a thermal zone before the zone's debugfs pointer is set which will result in a NULL pointer dereference in tze_seq_start().
Moreover, thermal_debug_tz_remove() is not called under the thermal zone lock, so it can run in parallel with the other functions accessing the thermal zone's struct thermal_debugfs object. Then, it may clear tz->debugfs after one of those functions has checked it and the struct thermal_debugfs object may be freed prematurely.
To address the first problem, pass a pointer to the thermal zone's struct thermal_debugfs object to debugfs_create_file() in thermal_debug_tz_add() and make tze_seq_start(), tze_seq_next(), tze_seq_stop(), and tze_seq_show() retrieve it from s->private instead of a pointer to the thermal zone object. This will ensure that tz_debugfs will be valid across the "mitigations" file accesses until thermal_debugfs_remove_id() called by thermal_debug_tz_remove() removes that file.
To address the second problem, use tz->lock in thermal_debug_tz_remove() around the tz->debugfs value check (in case the same thermal zone is removed at the same time in two different threads) and its reset to NULL.
Cc :6.8+ <[email protected]> # 6.8+
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Redhat_linux | — | Upgrade kernelUpgrade kernel-rtNo solution exists | Dec 5, 2024 | Jun 3, 2024 |
| Suse | — | Upgrade kernel-64kb-develUpgrade kernel-symsUpgrade reiserfs-kmp-defaultUpgrade kernel-defaultUpgrade kernel-docsUpgrade kernel-zfcpdumpUpgrade kernel-default-develUpgrade kernel-64kbUpgrade kernel-sourceUpgrade kernel-obs-buildUpgrade kernel-develUpgrade kernel-macros | Dec 5, 2025 | Dec 5, 2025 |
| Ubuntu | — | Upgrade linux-image-6.8.0-40-genericUpgrade linux-image-6.8.0-1010-oracle-64kUpgrade linux-image-6.8.0-1011-nvidia-64kUpgrade linux-image-6.8.0-1010-oracleUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-oracleUpgrade linux-image-6.8.0-1011-nvidia-lowlatencyUpgrade linux-image-6.8.0-1012-azure-fdeUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1011-nvidiaUpgrade linux-image-awsUpgrade linux-image-6.8.0-1012-gcpUpgrade linux-image-kvmUpgrade linux-image-6.8.0-1008-gkeUpgrade linux-image-6.8.0-1012-azureUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-nvidia-64k-6.8Upgrade linux-image-6.8.0-40-generic-64kUpgrade linux-image-6.8.0-1010-oemUpgrade linux-image-azure-fdeUpgrade linux-image-ibm-classicUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-lowlatency-64kUpgrade linux-image-virtualUpgrade linux-image-oem-24.04Upgrade linux-image-nvidia-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-lowlatencyUpgrade linux-image-6.8.0-1010-ibmUpgrade linux-image-gcpUpgrade linux-image-nvidiaUpgrade linux-image-generic-lpaeUpgrade linux-image-6.8.0-1011-nvidia-lowlatency-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-ibmUpgrade linux-image-6.8.0-1009-raspiUpgrade linux-image-raspiUpgrade linux-image-nvidia-6.8Upgrade linux-image-6.8.0-40-lowlatency-64kUpgrade linux-image-azureUpgrade linux-image-6.8.0-40-lowlatencyUpgrade linux-image-generic-64kUpgrade linux-image-oracle-64kUpgrade linux-image-genericUpgrade linux-image-6.8.0-1013-awsUpgrade linux-image-gke | Aug 9, 2024 | Jun 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub