CVE-2024-36476
A bug in the Linux kernel’s RDMA subsystem caused a null pointer dereference that could crash the system. The issue was fixed by moving a variable outside a block so it remains accessible throughout the function.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users, particularly those running versions prior to 6.13, including servers and embedded devices that rely on RDMA networking.
Real-world impact
An attacker could trigger a kernel crash, causing a denial‑of‑service or potentially enabling further exploitation if the crash can be leveraged for privilege escalation.
Why this severity
The CVSS score of 9.8 reflects the complete loss of confidentiality, integrity, and availability due to a kernel crash, combined with the fact that the vulnerability can be exploited remotely without authentication or user interaction.
What to do about it
- 01Upgrade the Linux kernel to version 6.13 or later.
- 02Reboot the system to load the updated kernel.
NVD description indicates fix applied.
Timeline
- Jan 15, 2025 · Jan 15, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/143378075904e78b3b…patch
- git.kernel.org/stable/c/32e1e748a85bd52b20…patch
- git.kernel.org/stable/c/6ffb5c1885195ae521…patch
- git.kernel.org/stable/c/7eaa71f56a6f7ab879…patch
- git.kernel.org/stable/c/b238f61cc394d5fef2…patch
- git.kernel.org/stable/c/fb514b31395946022f…patch
- lists.debian.org/debian-lts-announce/2025/03…
- lists.debian.org/debian-lts-announce/2025/03…