Back

MEDIUM

mac802154: fix missing INIT_LIST_HEAD in ieee802154_if_add()

Published Oct 21, 2024

Description

Kernel fault injection test reports null-ptr-deref as follows:

BUG: kernel NULL pointer dereference, address: 0000000000000008 RIP: 0010:cfg802154_netdev_notifier_call+0x120/0x310 include/linux/list.h:114 Call Trace: <TASK> raw_notifier_call_chain+0x6d/0xa0 kernel/notifier.c:87 call_netdevice_notifiers_info+0x6e/0xc0 net/core/dev.c:1944 unregister_netdevice_many_notify+0x60d/0xcb0 net/core/dev.c:1982 unregister_netdevice_queue+0x154/0x1a0 net/core/dev.c:10879 register_netdevice+0x9a8/0xb90 net/core/dev.c:10083 ieee802154_if_add+0x6ed/0x7e0 net/mac802154/iface.c:659 ieee802154_register_hw+0x29c/0x330 net/mac802154/main.c:229 mcr20a_probe+0xaaa/0xcb1 drivers/net/ieee802154/mcr20a.c:1316

ieee802154_if_add() allocates wpan_dev as netdev's private data, but not init the list in struct wpan_dev. cfg802154_netdev_notifier_call() manage the list when device register/unregister, and may lead to null-ptr-deref.

Use INIT_LIST_HEAD() on it to initialize it correctly.

Affected products

Remediation

Red Hat mitigation

If IEEE 802.15.4 wireless communication is not required, prevent the `mac802154` kernel module from loading by blacklisting it. To blacklist the module, create a file named `/etc/modprobe.d/blacklist-mac802154.conf` with the following content: ``` blacklist mac802154 ``` After creating the file, a system reboot or a reload of kernel modules is required for the change to take effect. This mitigation may impact functionality that relies on IEEE 802.15.4 devices.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Oct 21, 2024
Updated May 11, 2026
Reserved Aug 22, 2024
CISA Vulnrichment
Updated Oct 22, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 21, 2024