CVE-2024-45028
In the Linux kernel, the following vulnerability has been resolved: mmc: mmc_test: Fix NULL dereference on allocation failure If the "test->highmem = alloc_pages()" allocation fails then calling __free_pages(test->highmem) will result in a NULL…
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: mmc: mmc_test: Fix NULL dereference on allocation failure If the "test->highmem = alloc_pages()" allocation fails then calling __free_pages(test->highmem) will result in a NULL dereference. Also change the error code to -ENOMEM instead of returning success.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/2b507b03991f44dfb202fc2a82c9874d1b1f0c06Patch
- https://git.kernel.org/stable/c/3b4e76ceae5b5a46c968bd952f551ce173809f63Patch
- https://git.kernel.org/stable/c/9b9ba386d7bfdbc38445932c90fa9444c0524beaPatch
- https://git.kernel.org/stable/c/a1e627af32ed60713941cbfc8075d44cad07f6ddPatch
- https://git.kernel.org/stable/c/cac2815f49d343b2f0acc4973d2c14918ac3ab0cPatch
- https://git.kernel.org/stable/c/e40515582141a9e7c84b269be699c05236a499a6Patch
- https://git.kernel.org/stable/c/e97be13a9f51284da450dd2a592e3fa87b49cdc9Patch
- https://git.kernel.org/stable/c/ecb15b8ca12c0cbdab81e307e9795214d8b90890Patch
- https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.