CVE-2024-53056

⚪ Do wiadomości

NULL dereference w Linux kernel w mtk_crtc_destroy() może prowadzić do awarii systemu.

CVSS
5.5
EPSS
0.2%
Exploit
none
Vendor
linux
Opis źródłowy (NVD)

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy() In mtk_crtc_create(), if the call to mbox_request_channel() fails then we set the "mtk_crtc->cmdq_client.chan" pointer to NULL. In that situation, we do not call cmdq_pkt_create(). During the cleanup, we need to check if the "mtk_crtc->cmdq_client.chan" is NULL first before calling cmdq_pkt_destroy(). Calling cmdq_pkt_destroy() is unnecessary if we didn't call cmdq_pkt_create() and it will result in a NULL pointer dereference.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2024-11-19 18:15:25 UTC
Ostatnia modyfikacja (NVD)2026-10-03 11:17:32 UTC
Referencje