CVE-2024-26771
In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: edma: Add some null pointer checks to the edma_probe devm_kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: edma: Add some null pointer checks to the edma_probe devm_kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. Ensure the allocation was successful by checking the pointer validity.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/4fe4e5adc7d29d214c59b59f61db73dec505ca3dPatch
- https://git.kernel.org/stable/c/6e2276203ac9ff10fc76917ec9813c660f627369Patch
- https://git.kernel.org/stable/c/7b24760f3a3c7ae1a176d343136b6c25174b7b27Patch
- https://git.kernel.org/stable/c/9d508c897153ae8dd79303f7f035f078139f6b49Patch
- https://git.kernel.org/stable/c/c432094aa7c9970f2fa10d2305d550d3810657cePatch
- https://git.kernel.org/stable/c/f2a5e30d1e9a629de6179fa23923a318d5feb29ePatch
- https://git.kernel.org/stable/c/4fe4e5adc7d29d214c59b59f61db73dec505ca3dPatch
- https://git.kernel.org/stable/c/6e2276203ac9ff10fc76917ec9813c660f627369Patch
- https://git.kernel.org/stable/c/7b24760f3a3c7ae1a176d343136b6c25174b7b27Patch
- https://git.kernel.org/stable/c/9d508c897153ae8dd79303f7f035f078139f6b49Patch
- https://git.kernel.org/stable/c/c432094aa7c9970f2fa10d2305d550d3810657cePatch
- https://git.kernel.org/stable/c/f2a5e30d1e9a629de6179fa23923a318d5feb29ePatch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlMailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.