CVE-2024-56689

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: epf-mhi: Avoid NULL dereference if DT lacks 'mmio' If platform_get_resource_byname() fails and returns NULL because DT lacks an 'mmio' property for the MHI endpoint, dereferencing res->start will cause a NULL pointer access. Add a check to prevent it. [kwilczynski: error message update per the review feedback] [bhelgaas: commit log]
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

08 Jan 2025, 16:45

Type Values Removed Values Added
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/0e6d92e3b973de78eb7015154cf1197af9fac5c9 - () https://git.kernel.org/stable/c/0e6d92e3b973de78eb7015154cf1197af9fac5c9 - Patch
References () https://git.kernel.org/stable/c/242ee2b0ad9b23f47084904fce3f9f228068a1f9 - () https://git.kernel.org/stable/c/242ee2b0ad9b23f47084904fce3f9f228068a1f9 - Patch
References () https://git.kernel.org/stable/c/5089b3d874e9933d9842e90410d3af1520494757 - () https://git.kernel.org/stable/c/5089b3d874e9933d9842e90410d3af1520494757 - Patch
References () https://git.kernel.org/stable/c/c8b9d6b7d62a444e0bca5b9ae28f9f2b0f52feef - () https://git.kernel.org/stable/c/c8b9d6b7d62a444e0bca5b9ae28f9f2b0f52feef - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Summary
  • (es) En el núcleo de Linux, se ha resuelto la siguiente vulnerabilidad: PCI: endpoint: epf-mhi: Evitar la desreferenciación NULL si DT carece de 'mmio' Si platform_get_resource_byname() falla y devuelve NULL porque DT carece de una propiedad 'mmio' para el endpoint MHI, la desreferenciación de res->start provocará un acceso al puntero NULL. Agregue una verificación para evitarlo. [kwilczynski: actualización del mensaje de error según los comentarios de la revisión] [bhelgaas: registro de confirmaciones]

28 Dec 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-28 10:15

Updated : 2025-01-08 16:45


NVD link : CVE-2024-56689

Mitre link : CVE-2024-56689

CVE.ORG link : CVE-2024-56689


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference