{"id":"DEBIAN-CVE-2024-36926","details":"In the Linux kernel, the following vulnerability has been resolved:  powerpc/pseries/iommu: LPAR panics during boot up with a frozen PE  At the time of LPAR boot up, partition firmware provides Open Firmware property ibm,dma-window for the PE. This property is provided on the PCI bus the PE is attached to.  There are execptions where the partition firmware might not provide this property for the PE at the time of LPAR boot up. One of the scenario is where the firmware has frozen the PE due to some error condition. This PE is frozen for 24 hours or unless the whole system is reinitialized.  Within this time frame, if the LPAR is booted, the frozen PE will be presented to the LPAR but ibm,dma-window property could be missing.  Today, under these circumstances, the LPAR oopses with NULL pointer dereference, when configuring the PCI bus the PE is attached to.    BUG: Kernel NULL pointer dereference on read at 0x000000c8   Faulting instruction address: 0xc0000000001024c0   Oops: Kernel access of bad area, sig: 7 [#1]   LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries   Modules linked in:   Supported: Yes   CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.4.0-150600.9-default #1   Hardware name: IBM,9043-MRX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NM1060_023) hv:phyp pSeries   NIP:  c0000000001024c0 LR: c0000000001024b0 CTR: c000000000102450   REGS: c0000000037db5c0 TRAP: 0300   Not tainted  (6.4.0-150600.9-default)   MSR:  8000000002009033 \u003cSF,VEC,EE,ME,IR,DR,RI,LE\u003e  CR: 28000822  XER: 00000000   CFAR: c00000000010254c DAR: 00000000000000c8 DSISR: 00080000 IRQMASK: 0   ...   NIP [c0000000001024c0] pci_dma_bus_setup_pSeriesLP+0x70/0x2a0   LR [c0000000001024b0] pci_dma_bus_setup_pSeriesLP+0x60/0x2a0   Call Trace:     pci_dma_bus_setup_pSeriesLP+0x60/0x2a0 (unreliable)     pcibios_setup_bus_self+0x1c0/0x370     __of_scan_bus+0x2f8/0x330     pcibios_scan_phb+0x280/0x3d0     pcibios_init+0x88/0x12c     do_one_initcall+0x60/0x320     kernel_init_freeable+0x344/0x3e4     kernel_init+0x34/0x1d0     ret_from_kernel_user_thread+0x14/0x1c","modified":"2026-09-15T09:02:56.902422426Z","published":"2024-05-30T16:15:15.880Z","upstream":["CVE-2024-36926"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-36926"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.94-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-36926.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-36926.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-36926.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}