CVE-2024-50137
CBL Mariner vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel's StarFive JH7110 reset driver has been identified and assigned CVE-2024-50137. The issue was discovered in the reset controller functionality for the JH7110 SoC, specifically related to accessing an empty member in the data structure. This vulnerability affects Linux kernel versions from 6.4 up to (excluding) 6.11.6, as well as versions 6.12-rc1 through 6.12-rc3 (NVD).

Technical details

The vulnerability stems from a NULL pointer access in the StarFive JH7110 reset driver. The issue occurs when data->asserted is NULL on JH7110 SoC, which was introduced after commit 82327b127d41 ("reset: starfive: Add StarFive JH7110 reset driver"). The CVSS v3.1 base score is 5.5 (MEDIUM) with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

When exploited, this vulnerability could lead to errors when calling resetcontrolstatus on JH7110 SoC, potentially causing system instability or denial of service conditions due to improper handling of NULL pointer access (Kernel Patch).

Mitigation and workarounds

A fix has been implemented through a patch that adds a judgment condition to avoid errors when calling resetcontrolstatus on JH7110 SoC. The patch has been merged into the Linux kernel and is available in newer versions. Users are advised to update their systems to patched versions (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related CBL Mariner vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66031HIGH8.7
  • JavaScriptJavaScript
  • kibana-8.17
NoYesNov 26, 2025
CVE-2025-12638HIGH8
  • CBL MarinerCBL Mariner
  • keras
NoYesNov 28, 2025
CVE-2025-13601HIGH7.7
  • CBL MarinerCBL Mariner
  • glib2
NoYesNov 26, 2025
CVE-2025-66293HIGH7.1
  • OpenJDK JDKOpenJDK JDK
  • java-21-openjdk-headless-slowdebug
NoYesDec 03, 2025
CVE-2025-66030MEDIUM6.3
  • JavaScriptJavaScript
  • kibana-8.18
NoYesNov 26, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management