CVE-2024-26879: clk: meson: Add missing clocks to axg_clk_regmaps

Published Apr 17, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

clk: meson: Add missing clocks to axgclkregmaps

Some clocks were missing from axgclkregmaps, which caused kernel panic during cat /sys/kernel/debug/clk/clksummary

[ 57.349402] Unable to handle kernel NULL pointer dereference at virtual address 00000000000001fc ... [ 57.430002] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 57.436900] pc : regmapread+0x1c/0x88 [ 57.440608] lr : clkregmapgateisenabled+0x3c/0xb0 [ 57.445611] sp : ffff800082f1b690 [ 57.448888] x29: ffff800082f1b690 x28: 0000000000000000 x27: ffff800080eb9a70 [ 57.455961] x26: 0000000000000007 x25: 0000000000000016 x24: 0000000000000000 [ 57.463033] x23: ffff800080e8b488 x22: 0000000000000015 x21: ffff00000e7e7000 [ 57.470106] x20: ffff00000400ec00 x19: 0000000000000000 x18: ffffffffffffffff [ 57.477178] x17: 0000000000000000 x16: 0000000000000000 x15: ffff0000042a3000 [ 57.484251] x14: 0000000000000000 x13: ffff0000042a2fec x12: 0000000005f5e100 [ 57.491323] x11: abcc77118461cefd x10: 0000000000000020 x9 : ffff8000805e4b24 [ 57.498396] x8 : ffff0000028063c0 x7 : ffff800082f1b710 x6 : ffff800082f1b710 [ 57.505468] x5 : 00000000ffffffd0 x4 : ffff800082f1b6e0 x3 : 0000000000001000 [ 57.512541] x2 : ffff800082f1b6e4 x1 : 000000000000012c x0 : 0000000000000000 [ 57.519615] Call trace: [ 57.522030] regmapread+0x1c/0x88 [ 57.525393] clkregmapgateisenabled+0x3c/0xb0 [ 57.530050] clkcoreisenabled+0x44/0x120 [ 57.534190] clksummaryshowsubtree+0x154/0x2f0 [ 57.538847] clksummaryshowsubtree+0x220/0x2f0 [ 57.543505] clksummaryshowsubtree+0x220/0x2f0 [ 57.548162] clksummaryshowsubtree+0x220/0x2f0 [ 57.552820] clksummaryshowsubtree+0x220/0x2f0 [ 57.557477] clksummaryshowsubtree+0x220/0x2f0 [ 57.562135] clksummaryshowsubtree+0x220/0x2f0 [ 57.566792] clksummaryshowsubtree+0x220/0x2f0 [ 57.571450] clksummaryshow+0x84/0xb8 [ 57.575245] seqreaditer+0x1bc/0x4b8 [ 57.578954] seqread+0x8c/0xd0 [ 57.582059] fullproxyread+0x68/0xc8 [ 57.585767] vfsread+0xb0/0x268 [ 57.588959] ksysread+0x70/0x108 [ 57.592236] arm64sysread+0x24/0x38 [ 57.596031] invokesyscall+0x50/0x128 [ 57.599740] el0svccommon.constprop.0+0x48/0xf8 [ 57.604397] doel0svc+0x28/0x40 [ 57.607675] el0svc+0x34/0xb8 [ 57.610694] el0t64synchandler+0x13c/0x158 [ 57.615006] el0t64sync+0x190/0x198 [ 57.618635] Code: a9bd7bfd 910003fd a90153f3 aa0003f3 (b941fc00) [ 57.624668] ---[ end trace 0000000000000000 ]---

[jbrunet: add missing Fixes tag]

Affected Software

6 affected componentsFixes available
Linux Linux kernel>=5.11<5.15.153
Linux Linux kernel>=5.16<6.1.83
Linux Linux kernel>=6.2<6.6.23
Linux Linux kernel>=6.7<6.7.11
Linux Linux kernel>=6.8<6.8.2
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Apr 17, 2024
CVE Published
via MITRE·10:27 AM
Data Sourced
via MITRE·10:27 AM
Description
Jun 8, 2024
Data Sourced
via Launchpad·01:08 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·02:21 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-26879?

The severity of CVE-2024-26879 is classified as moderate, as it can lead to kernel panic under specific conditions.

2

How do I fix CVE-2024-26879?

To fix CVE-2024-26879, upgrade to the latest recommended versions of the Linux kernel, such as 5.10.223-1, 6.1.119-1, or later.

3

Which Linux kernel versions are affected by CVE-2024-26879?

CVE-2024-26879 affects Linux kernel versions from 5.11 to 6.8.2.

4

What issues are caused by CVE-2024-26879?

CVE-2024-26879 can lead to a kernel panic when executing certain commands related to clock management.

5

Is CVE-2024-26879 fixed in future kernel updates?

Yes, CVE-2024-26879 has been resolved in subsequent kernel updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203