5.5

CVE-2024-53115

drm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle

The 'vmw_user_object_buffer' function may return NULL with incorrect
inputs. To avoid possible null pointer dereference, add a check whether
the 'bo' is NULL in the vmw_framebuffer_surface_create_handle.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.10.4 < 6.11
Linux ≫ Linux Kernel Version >= 6.11 < 6.11.10
Linux ≫ Linux Kernel Version 6.12 Update rc1
Linux ≫ Linux Kernel Version 6.12 Update rc2
Linux ≫ Linux Kernel Version 6.12 Update rc3
Linux ≫ Linux Kernel Version 6.12 Update rc4
Linux ≫ Linux Kernel Version 6.12 Update rc5
Linux ≫ Linux Kernel Version 6.12 Update rc6
Linux ≫ Linux Kernel Version 6.12 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://git.kernel.org/stable/c/36f64da080555175b58d85f99f5f90435e274e56
Patch
https://git.kernel.org/stable/c/93d1f41a82de382845af460bf03bcb17dcbf08c5
Patch