CVE-2024-36481
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-36481 is a vulnerability in the Linux kernel's tracing/probes subsystem, discovered and disclosed on June 21, 2024. The issue affects the parsebtffield() function where btffindstructmember() might return NULL or an error via the ERRPTR() macro, but its caller only checks for the NULL condition (CVE, Ubuntu).

Technical details

The vulnerability exists in the kernel's tracing probe functionality where the parsebtffield() function fails to properly handle error conditions returned by btffindstructmember(). The function only checks for NULL returns but doesn't properly handle error cases that could be returned via the ERRPTR() macro. The issue has been assigned a CVSS 3 Severity Score of 5.5 (Medium) (Ubuntu).

Impact

The vulnerability could potentially lead to system instability or denial of service conditions when processing BTF (BPF Type Format) field access in the Linux kernel's tracing subsystem (Rapid7).

Mitigation and workarounds

The vulnerability has been fixed in multiple Linux kernel versions. The fix involves using IS_ERR() to properly check for and handle error conditions, returning the error up the stack. Updates are available for various Ubuntu releases including 24.04 LTS (noble) with kernel version 6.8.0-44.44 and other kernel variants (Ubuntu, Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40258HIGH7
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-devel-matched
NoNoDec 04, 2025
CVE-2025-40259MEDIUM6.2
  • Linux KernelLinux Kernel
  • kernel-64k-devel
NoNoDec 04, 2025
CVE-2025-40264MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoNoDec 04, 2025
CVE-2025-40254MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-modules-partner
NoNoDec 04, 2025
CVE-2025-40253MEDIUM5.5
  • Linux KernelLinux Kernel
  • python3-perf
NoNoDec 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management