Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-24856

Опубликовано: 17 апр. 2024
Источник: debian
EPSS Низкий

Описание

The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer that receives it, which may lead to null pointer dereference. To fix this issue, a null pointer check should be added. If it is null, return exception code AE_NO_MEMORY.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
acpica-unixfixed20240827-2package

Примечания

  • https://bugzilla.openanolis.cn/show_bug.cgi?id=8764

  • https://github.com/acpica/acpica/pull/946

  • https://github.com/acpica/acpica/commit/4d4547cf13cca820ff7e0f859ba83e1a610b9fd0 (version-20240827)

  • Crash in CLI tool, no security impact

EPSS

Процентиль: 7%
0.00172
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer that receives it, which may lead to null pointer dereference. To fix this issue, a null pointer check should be added. If it is null, return exception code AE_NO_MEMORY.

CVSS3: 5.3
nvd
больше 2 лет назад

The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer that receives it, which may lead to null pointer dereference. To fix this issue, a null pointer check should be added. If it is null, return exception code AE_NO_MEMORY.

msrc
9 месяцев назад

NULL pointer deference in acpi_db_convert_to_package of Linux acpi module

CVSS3: 5.3
github
больше 2 лет назад

The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer that receives it, which may lead to null pointer dereference. To fix this issue, a null pointer check should be added. If it is null, return exception code AE_NO_MEMORY.

CVSS3: 5.3
fstec
больше 3 лет назад

Уязвимость функции acpi_db_display_objects() модуля drivers/acpi/acpica/dbconvert.c - драйвера поддержки ACPI (расширенный интерфейс конфигурации и питания) ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 7%
0.00172
Низкий