CVE-2024-46739
uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
18 sep 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
In the Linux kernel, the following vulnerability has been resolved:
uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind
For primary VM Bus channels, primary_channel pointer is always NULL. This
pointer is valid only for the secondary channels. Also, rescind callback
is meant for primary channels only.
Fix NULL pointer dereference by retrieving the device_obj from the parent
for the primary channel.
Productos afectados
Linux · Linux¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://git.kernel.org/stable/c/1d8e020e51ab07e40f9dd00b52f1da7d96fec04chttps://git.kernel.org/stable/c/2be373469be1774bbe03b0fa7e2854e65005b1cchttps://git.kernel.org/stable/c/3005091cd537ef8cdb7530dcb2ecfba8d2ef475chttps://git.kernel.org/stable/c/3d414b64ecf6fd717d7510ffb893c6f23acbf50ehttps://git.kernel.org/stable/c/928e399e84f4e80307dce44e89415115c473275bhttps://git.kernel.org/stable/c/de6946be9c8bc7d2279123433495af7c21011b99https://git.kernel.org/stable/c/f38f46da80a2ab7d1b2f8fcb444c916034a2dac4https://git.kernel.org/stable/c/fb1adbd7e50f3d2de56d0a2bb0700e2e819a329ehttps://lists.debian.org/debian-lts-announce/2024/10/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2025/01/msg00001.html