LiveActive security incident?Get immediate response
CVE Record

CVE-2024-36023: Julia Lawall reported this null pointer dereference, this should fix it.

In the Linux kernel, the following vulnerability has been resolved: Julia Lawall reported this null pointer dereference, this should fix it.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2024-36023 is a Linux kernel null pointer dereference fixed in upstream stable commits. The public record is sparse: it does not name a subsystem, business impact, CVSS score, or exploitation path. Organizations should handle it through standard kernel patch governance and confirm vendor backports.

Executive priority

Moderate operational priority until more impact data appears. Keep it in the normal kernel security update cycle, escalating for internet-facing infrastructure, shared compute, or high-availability systems where kernel faults could cause outages.

Technical view

The CVE record says a null pointer dereference reported by Julia Lawall was resolved in the Linux kernel. The source bundle lists affected Linux versions and four stable commit references. It does not provide CWE, CVSS, reachable attack surface, privilege requirements, or subsystem context.

Likely exposure

Exposure applies to systems running affected Linux kernel builds or downstream packages that lack the referenced stable fixes. Validate by distribution package status, not upstream version strings alone, because Linux vendors often backport security fixes.

Exploitation context

The source bundle does not show CISA KEV listing, public exploitation, exploit availability, or attack prerequisites. Active exploitation should not be assumed from the provided evidence.

Researcher notes

Key unknowns are subsystem, trigger conditions, privilege boundary, and impact beyond null pointer dereference. Review the stable commits and downstream advisories before assigning exploitability or severity. Do not infer remote exposure from the current CVE text.

Mitigation direction

  • Prioritize kernel updates from your Linux distribution or appliance vendor.
  • Confirm deployed kernels include a referenced stable fix or downstream equivalent.
  • Monitor vendor advisories for subsystem-specific mitigations or reboot requirements.
  • Schedule reboots or live patching through approved kernel maintenance processes.

Validation and detection

  • Inventory kernel versions across servers, container hosts, and appliances.
  • Map package changelogs to referenced stable commits or vendor CVE notices.
  • Check scanner findings against distribution backport status.
  • Record exceptions where no vendor fix confirmation exists.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-36023 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
5Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxf7ab093f74bf638ed98fd1115f3efa17e308bb7f, f7ab093f74bf638ed98fd1115f3efa17e308bb7f, f7ab093f74bf638ed98fd1115f3efa17e308bb7f, f7ab093f74bf638ed98fd1115f3efa17e308bb7funaffected
LinuxLinux4.6, 0, 6.1.86, 6.6.27, 6.8.6, 6.9affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.