{"id":"DEBIAN-CVE-2024-36961","details":"In the Linux kernel, the following vulnerability has been resolved:  thermal/debugfs: Fix two locking issues with thermal zone debug  With the current thermal zone locking arrangement in the debugfs code, user space can open the \"mitigations\" file for a thermal zone before the zone's debugfs pointer is set which will result in a NULL pointer dereference in tze_seq_start().  Moreover, thermal_debug_tz_remove() is not called under the thermal zone lock, so it can run in parallel with the other functions accessing the thermal zone's struct thermal_debugfs object.  Then, it may clear tz-\u003edebugfs after one of those functions has checked it and the struct thermal_debugfs object may be freed prematurely.  To address the first problem, pass a pointer to the thermal zone's struct thermal_debugfs object to debugfs_create_file() in thermal_debug_tz_add() and make tze_seq_start(), tze_seq_next(), tze_seq_stop(), and tze_seq_show() retrieve it from s-\u003eprivate instead of a pointer to the thermal zone object.  This will ensure that tz_debugfs will be valid across the \"mitigations\" file accesses until thermal_debugfs_remove_id() called by thermal_debug_tz_remove() removes that file.  To address the second problem, use tz-\u003elock in thermal_debug_tz_remove() around the tz-\u003edebugfs value check (in case the same thermal zone is removed at the same time in two different threads) and its reset to NULL.  Cc :6.8+ \u003cstable@vger.kernel.org\u003e # 6.8+","modified":"2026-10-01T11:01:54.335368709Z","published":"2024-06-03T08:15:09.660Z","upstream":["CVE-2024-36961"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-36961"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-36961.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-36961.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}