Vulnerabilities > CVE-2024-58011 - Unspecified vulnerability in Linux Kernel
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
In the Linux kernel, the following vulnerability has been resolved: platform/x86: int3472: Check for adev == NULL Not all devices have an ACPI companion fwnode, so adev might be NULL. This can e.g. (theoretically) happen when a user manually binds one of the int3472 drivers to another i2c/platform device through sysfs. Add a check for adev not being set and return -ENODEV in that case to avoid a possible NULL pointer deref in skl_int3472_get_acpi_buffer().
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 |
References
- https://git.kernel.org/stable/c/0a30353beca2693d30bde477024d755ffecea514
- https://git.kernel.org/stable/c/4f8b210823cc2d1f9d967f089a6c00d025bb237f
- https://git.kernel.org/stable/c/a808ecf878ad646ebc9c83d9fc4ce72fd9c49d3d
- https://git.kernel.org/stable/c/cd2fd6eab480dfc247b737cf7a3d6b009c4d0f1c
- https://git.kernel.org/stable/c/f9c7cc44758f4930b41285a6d54afa8cbd9762b4