CVE-2024-39470

CVSS v3.1 5.5 (Medium)
55% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 1
Advisories 5
NVD Status Analyzed

In the Linux kernel, the following vulnerability has been resolved:

eventfs: Fix a possible null pointer dereference in eventfs_find_events()

In function eventfs_find_events,there is a potential null pointer
that may be caused by calling update_events_attr which will perform
some operations on the members of the ei struct when ei is NULL.

Hence,When ei->is_freed is set,return NULL directly.

Weaknesses
CWE-476
NULL Pointer Dereference
CVE Status
PUBLISHED
NVD Status
Analyzed
CNA
kernel.org
Published Date
2024-06-25 15:15:15
(2 months ago)
Updated Date
2024-08-19 20:58:03
(4 weeks ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 6.6.18 version and prior 6.6.34 version cpe:2.3:o:linux:linux_kernel >= 6.6.18 < 6.6.34
  Linux Kernel from 6.8 version and prior 6.9.5 version cpe:2.3:o:linux:linux_kernel >= 6.8 < 6.9.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...