Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-12-28 CVE-2024-56697 NULL Pointer Dereference vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix the memory allocation issue in amdgpu_discovery_get_nps_info() Fix two issues with memory allocation in amdgpu_discovery_get_nps_info() for mem_ranges: - Add a check for allocation failure to avoid dereferencing a null pointer. - As suggested by Christophe, use kvcalloc() for memory allocation, which checks for multiplication overflow. Additionally, assign the output parameters nps_type and range_cnt after the kvcalloc() call to prevent modifying the output parameters in case of an error return.
local
low complexity
linux CWE-476
5.5
2024-12-28 CVE-2024-56698 NULL Pointer Dereference vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Fix looping of queued SG entries The dwc3_request->num_queued_sgs is decremented on completion.
local
low complexity
linux CWE-476
5.5
2024-12-28 CVE-2024-56702 NULL Pointer Dereference vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: bpf: Mark raw_tp arguments with PTR_MAYBE_NULL Arguments to a raw tracepoint are tagged as trusted, which carries the semantics that the pointer will be non-NULL.
local
low complexity
linux CWE-476
5.5
2024-12-28 CVE-2024-56704 Double Free vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: 9p/xen: fix release of IRQ Kernel logs indicate an IRQ was double-freed. Pass correct device ID during IRQ release. [Dominique: remove confusing variable reset to 0]
local
low complexity
linux CWE-415
7.8
2024-12-28 CVE-2024-56708 Double Free vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Avoid segmentation fault on module unload The segmentation fault happens because: During modprobe: 1.
local
low complexity
linux CWE-415
7.8
2024-12-28 CVE-2023-52718 Unspecified vulnerability in Huawei products
A connection hijacking vulnerability exists in some Huawei home routers.
low complexity
huawei
8.1
2024-12-28 CVE-2020-1820 Out-of-bounds Read vulnerability in Huawei products
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products.
network
low complexity
huawei CWE-125
5.3
2024-12-28 CVE-2020-1821 Out-of-bounds Read vulnerability in Huawei products
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products.
network
low complexity
huawei CWE-125
5.3
2024-12-28 CVE-2020-1822 Out-of-bounds Read vulnerability in Huawei products
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products.
network
low complexity
huawei CWE-125
5.3
2024-12-28 CVE-2020-1823 Out-of-bounds Read vulnerability in Huawei products
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products.
network
low complexity
huawei CWE-125
5.3