git.kernel.org
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git CVE-2024-38573
HIGH
cppc_cpufreq: Fix possible null pointer dereference
Record summary
CVE-2024-38573 has a selected CVSS score of 7.5 (high).
Description
In the Linux kernel, the following vulnerability has been resolved: cppc_cpufreq: Fix possible null pointer dereference cppc_cpufreq_get_rate() and hisi_cppc_cpufreq_get_rate() can be called from different places with various parameters. So cpufreq_cpu_get() can return null as 'policy' in some circumstances. Fix this bug by adding null return check. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 27, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
LinuxBrowse Linux / LinuxDefault status: unaffected, affected | CVE List | a28b2bfc099c6b9caa6ef697660408e076a32019 to < 9a185cc5a79ba408e1c73375706630662304f618 | affected |
| a28b2bfc099c6b9caa6ef697660408e076a32019 to < 769c4f355b7962895205b86ad35617873feef9a5 | affected | ||
| a28b2bfc099c6b9caa6ef697660408e076a32019 to < f84b9b25d045e67a7eee5e73f21278c8ab06713c | affected | ||
| a28b2bfc099c6b9caa6ef697660408e076a32019 to < b18daa4ec727c0266de5bfc78e818d168cc4aedf | affected | ||
| a28b2bfc099c6b9caa6ef697660408e076a32019 to < dfec15222529d22b15e5b0d63572a9e39570cab4 | affected | ||
| a28b2bfc099c6b9caa6ef697660408e076a32019 to < cf7de25878a1f4508c69dc9f6819c21ba177dbfe | affected | ||
| 5.11 | affected | ||
| Before 5.11 | unaffected | ||
| 5.15.161 to ≤ 5.15.* | unaffected | ||
| 6.1.93 to ≤ 6.1.* | unaffected | ||
| 6.6.33 to ≤ 6.6.* | unaffected | ||
| 6.8.12 to ≤ 6.8.* | unaffected | ||
| Showing 12 of 14 version ranges | |||
Default status: unknown | CVE List | a28b2bfc099c to < cf7de25878a1 | affected |
linux_kernelBrowse linux / linux_kernelDefault status: unknown | CVE List | a28b2bfc099c to < 9a185cc5a79b | affected |
| a28b2bfc099c to < 769c4f355b79 | affected | ||
| 6.6.33 to ≤ 6.7 | unaffected | ||
| 6.8.12 to ≤ 6.9 | unaffected | ||
| 6.9.3 to ≤ 6.10 | unaffected | ||
| 6.10-rc1 | unaffected | ||
| a28b2bfc099c to < f84b9b25d045 | affected | ||
| a28b2bfc099c to < b18daa4ec727 | affected | ||
| a28b2bfc099c to < dfec15222529 | affected | ||
| 5.11 | affected | ||
| Before 5.11 | unaffected | ||
| 5.15.161 to ≤ 5.16 | unaffected | ||
| Showing 12 of 13 version ranges | |||
KernelBrowse Linux / Kernel | OSV | 5.11.0 to < 5.15.161 · Fixed in 5.15.161 | affected |
| 5.16.0 to < 6.1.93 · Fixed in 6.1.93 | affected | ||
| 6.2.0 to < 6.6.33 · Fixed in 6.6.33 | affected | ||
| 6.7.0 to < 6.8.12 · Fixed in 6.8.12 | affected | ||
| 6.9.0 to < 6.9.3 · Fixed in 6.9.3 | affected | ||
References
9git.kernel.org
https://git.kernel.org/stable/c/769c4f355b7962895205b86ad35617873feef9a5 git.kernel.org
https://git.kernel.org/stable/c/9a185cc5a79ba408e1c73375706630662304f618 git.kernel.org
https://git.kernel.org/stable/c/b18daa4ec727c0266de5bfc78e818d168cc4aedf git.kernel.org
https://git.kernel.org/stable/c/cf7de25878a1f4508c69dc9f6819c21ba177dbfe git.kernel.org
https://git.kernel.org/stable/c/dfec15222529d22b15e5b0d63572a9e39570cab4 git.kernel.org
https://git.kernel.org/stable/c/f84b9b25d045e67a7eee5e73f21278c8ab06713c github.com
https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38573.json nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-38573