5.3
CVE-2024-24856
- EPSS 0.17%
- Veröffentlicht 17.04.2024 09:15:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle security@openanolis.org
- CVE-Watchlists
- Unerledigt
NULL pointer deference in acpi_db_convert_to_package of Linux acpi module
The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer that receives it, which may lead to null pointer dereference. To fix this issue, a null pointer check should be added. If it is null, return exception code AE_NO_MEMORY.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstelleropenanolis
≫
Produkt
anolis_os
Default Statusunaffected
Version
v4.4
Version <
v6.9
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.067 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@openanolis.org | 5.3 | 0.8 | 4 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://bugzilla.openanolis.cn/show_bug.cgi?id=8764