CVE-2024-58068: OPP: fix dev_pm_opp_find_bw_*() when bandwidth table not initialized
In the Linux kernel, the following vulnerability has been resolved:
OPP: fix dev_pm_opp_find_bw_*() when bandwidth table not initialized
If a driver calls dev_pm_opp_find_bw_ceil/floor() the retrieve bandwidth
from the OPP table but the bandwidth table was not created because the
interconnect properties were missing in the OPP consumer node, the
kernel will crash with:
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004
...
pc : _read_bw+0x8/0x10
lr : _opp_table_find_key+0x9c/0x174
...
Call trace:
_read_bw+0x8/0x10 (P)
_opp_table_find_key+0x9c/0x174 (L)
_find_key+0x98/0x168
dev_pm_opp_find_bw_ceil+0x50/0x88
...
In order to fix the crash, create an assert function to check
if the bandwidth table was created before trying to get a
bandwidth with _read_bw().
Security readout for executives and security teams
Plain-English summary
CVE-2024-58068 is a Linux kernel availability flaw. A driver can trigger a kernel crash when it asks the OPP subsystem for bandwidth data that was never initialized. The main business impact is local denial of service, not data theft or remote compromise based on the provided sources.
Executive priority
Treat this as a moderate patch-management item. Prioritize internet-independent but uptime-critical Linux appliances, embedded systems, and custom kernel fleets where local users or workloads can trigger kernel paths that affect availability.
Technical view
The bug is a NULL pointer dereference in Linux OPP bandwidth lookup. If dev_pm_opp_find_bw_ceil() or dev_pm_opp_find_bw_floor() is called when the bandwidth table was not created because interconnect properties are missing, _read_bw() can crash the kernel. The fix adds a check before reading bandwidth data.
Likely exposure
Exposure is limited to affected Linux kernels with drivers using the OPP bandwidth lookup path and missing interconnect properties. The CVSS vector indicates local access and low privileges are required. Embedded, device, or custom kernel environments should verify vendor kernel status carefully.
Exploitation context
The source bundle does not show active exploitation, and CISA KEV status is false. The documented impact is a kernel crash, causing availability loss. No confidentiality or integrity impact is identified in the provided CVSS data.
Researcher notes
Evidence supports CWE-476 and availability-only impact. The vulnerable condition is specific: OPP bandwidth lookup without an initialized bandwidth table. The bundle does not provide exploit reports, affected distribution breadth beyond listed Linux data, or a generic runtime workaround.
Mitigation direction
Update affected Linux kernels to vendor releases containing the referenced stable fixes.
Use Debian LTS guidance if managing Debian systems covered by the advisory.
For custom kernels, verify the relevant stable commit is present before release.
Check vendor guidance for downstream kernel packages and device firmware updates.
Validation and detection
Inventory deployed Linux kernel versions against the CVE affected-version data.
Confirm whether the kernel tree includes one of the referenced stable fixes.
Review crash logs for NULL dereferences involving _read_bw or dev_pm_opp_find_bw_ceil.
Identify platforms using OPP bandwidth lookup paths with interconnect-dependent configuration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-476: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.