PT-2024-29748 · Linux+4 · Linux Kernel+4

·

CVE-2024-42107

·

Published

2024-07-02

·

Updated

2026-08-25

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises from a race condition between the ice ptp extts event() function and ice ptp release(), leading to a NULL pointer dereference and resulting in a kernel panic. This occurs because ice ptp extts event() calls ptp clock event() with a NULL pointer after the ice driver has released the PTP clock. The problem can be resolved by modifying the ice ptp extts event() function to check the PTP state and exit early if PTP is not ready.
Recommendations To fix this issue, modify the ice ptp extts event() function to check the PTP state and bail early if PTP is not ready. As a temporary workaround, consider disabling the ice ptp extts event() function until a patch is available. Restrict access to the PTP clock to minimize the risk of exploitation. Avoid using the ptp clock event() function with a NULL pointer in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2025-12647
AZL-55184
AZL-55217
BDU:2025-16203
CVE-2024-42107
ECHO-7B78-9321-7C9F
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3483-1
RHSA-2024:5672
RHSA-2024:5673
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3483-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1

Affected Products

Alt Linux
Astra Linux
Debian
Linux Kernel
Suse