Vulnerabilities > CVE-2024-27048 - NULL Pointer Dereference vulnerability in Linux Kernel
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: handle pmk_op allocation failure The kzalloc() in brcmf_pmksa_v3_op() will return null if the physical memory has run out. As a result, if we dereference the null value, the null pointer dereference bug will happen. Return -ENOMEM from brcmf_pmksa_v3_op() if kzalloc() fails for pmk_op.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://git.kernel.org/stable/c/6138a82f3bccfc67ed7ac059493579fc326c02e5
- https://git.kernel.org/stable/c/6138a82f3bccfc67ed7ac059493579fc326c02e5
- https://git.kernel.org/stable/c/9975908315c13bae2f2ed5ba92870fa935180b0e
- https://git.kernel.org/stable/c/9975908315c13bae2f2ed5ba92870fa935180b0e
- https://git.kernel.org/stable/c/b4152222e04cb8afeeca239c90e3fcaf4c553b42
- https://git.kernel.org/stable/c/b4152222e04cb8afeeca239c90e3fcaf4c553b42
- https://git.kernel.org/stable/c/df62e22c2e27420e8990a4f09e30d7bf56c2036f
- https://git.kernel.org/stable/c/df62e22c2e27420e8990a4f09e30d7bf56c2036f