Tracker / CVE-2024-46822
CVE-2024-46822
Media 5.5
In the Linux kernel, the following vulnerability has been resolved: arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry In a review discussion of the changes to support vCPU hotplug where a check was added on the GICC being enabled if was online, it was noted that there is need to map back to the cpu and use that to index into a cpumask. As such, a valid ID is needed. If an MPIDR check fails in acpi_map_gic_cpu_interface() it is possible for the entry in cpu_madt_gicc[cpu] == NULL. This function would then cause a NULL pointer dereference. Whilst a path to trigger this has not been established, harden this caller against the possibility.
Prodotti e versioni affette
| linux | linux_kernel · … → 5.4.284 |
|---|---|
| linux | linux_kernel · 5.11 → 5.15.167 |
| linux | linux_kernel · 5.16 → 6.1.110 |
| linux | linux_kernel · 5.5 → 5.10.226 |
| linux | linux_kernel · 6.2 → 6.6.51 |
| linux | linux_kernel · 6.7 → 6.10.10 |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.