CVE-2024-42277

MEDIUM EPSS 13.2%
Published Aug 17, 20241y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Aug 17, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: iommu: sprd: Avoid NULL deref in sprd_iommu_hw_en In sprd_iommu_cleanup() before calling function sprd_iommu_hw_en() dom->sdev is equal to NULL, which leads to null dereference. Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
13.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 4

VendorProductVersionRange
linuxlinux_kernel*≥5.15.113  –  <5.15.165
linuxlinux_kernel*≥6.1.81  –  <6.1.103
linuxlinux_kernel*≥6.3.4  –  <6.6.44
linuxlinux_kernel*≥6.7  –  <6.10.3

References 6

  • git.kernel.org https://git.kernel.org/stable/c/630482ee0653decf9e2482ac6181897eb6cde5b8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8c79ceb4ecf823e6ec10fee6febb0fca3de79922
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b62841e49a2b7938f6fdeaaf93fb57e4eb880bdb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d5fe884ce28c5005f8582c35333c195a168f841c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/dfe90030a0cfa26dca4cb6510de28920e5ad22fb
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/630482ee0653decf9e2482ac6181897eb6cde5b8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8c79ceb4ecf823e6ec10fee6febb0fca3de79922
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b62841e49a2b7938f6fdeaaf93fb57e4eb880bdb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d5fe884ce28c5005f8582c35333c195a168f841c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/dfe90030a0cfa26dca4cb6510de28920e5ad22fb
    Patch