{"id":"DEBIAN-CVE-2024-26731","details":"In the Linux kernel, the following vulnerability has been resolved:  bpf, sockmap: Fix NULL pointer dereference in sk_psock_verdict_data_ready()  syzbot reported the following NULL pointer dereference issue [1]:    BUG: kernel NULL pointer dereference, address: 0000000000000000   [...]   RIP: 0010:0x0   [...]   Call Trace:    \u003cTASK\u003e    sk_psock_verdict_data_ready+0x232/0x340 net/core/skmsg.c:1230    unix_stream_sendmsg+0x9b4/0x1230 net/unix/af_unix.c:2293    sock_sendmsg_nosec net/socket.c:730 [inline]    __sock_sendmsg+0x221/0x270 net/socket.c:745    ____sys_sendmsg+0x525/0x7d0 net/socket.c:2584    ___sys_sendmsg net/socket.c:2638 [inline]    __sys_sendmsg+0x2b0/0x3a0 net/socket.c:2667    do_syscall_64+0xf9/0x240    entry_SYSCALL_64_after_hwframe+0x6f/0x77  If sk_psock_verdict_data_ready() and sk_psock_stop_verdict() are called concurrently, psock-\u003esaved_data_ready can be NULL, causing the above issue.  This patch fixes this issue by calling the appropriate data ready function using the sk_psock_data_ready() helper and protecting it from concurrency with sk-\u003esk_callback_lock.","modified":"2026-09-15T09:03:05.209903110Z","published":"2024-04-03T17:15:50.927Z","upstream":["CVE-2024-26731"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-26731"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.82-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26731.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26731.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26731.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}