5.5
CVE-2024-40973
- EPSS 0.29%
- Veröffentlicht 12.07.2024 13:15:18
- Zuletzt bearbeitet 23.08.2026 13:16:24
- Erkennungen
media: mtk-vcodec: potential null pointer deference in SCP
In the Linux kernel, the following vulnerability has been resolved: media: mtk-vcodec: potential null pointer deference in SCP The return value of devm_kzalloc() needs to be checked to avoid NULL pointer deference. This is similar to CVE-2022-3113.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 6.6.36
Linux ≫ Linux Kernel Version >= 6.7 < 6.9.7
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.205 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://git.kernel.org/stable/c/3a693c7e243b932faee5c1fb728efa73f0abc39b
https://git.kernel.org/stable/c/53dbe08504442dc7ba4865c09b3bbf5fe849681b
https://git.kernel.org/stable/c/f066882293b5ad359e44c4ed24ab1811ffb0b354
https://git.kernel.org/stable/c/eeb62bb4ca22db17f7dfe8fb8472e0442df3d92f
https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
https://git.kernel.org/stable/c/19ef02106c990bf4235365a08b9d8d2fee37272a
https://git.kernel.org/stable/c/ac79a923365ae1e524398087cf16313cdbd7a144